Information Disclosure Vulnerability in Microsoft Windows ETL Channel
CVE-2025-59197

5.5MEDIUM

What is CVE-2025-59197?

An information disclosure vulnerability has been identified in the Windows ETL Channel, which may allow an authorized attacker to insert sensitive information into log files. This could enable the attacker to leverage this data for unauthorized purposes, posing risks to data integrity and confidentiality. Users are advised to monitor log file activities and apply relevant security measures to mitigate potential risks.

Affected Version(s)

Windows 10 Version 1507 32-bit Systems 10.0.10240.0 < 10.0.10240.21161

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.8519

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.7919

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59197 : Information Disclosure Vulnerability in Microsoft Windows ETL Channel