Sensitive Information Disclosure in Windows StateRepository API by Microsoft
CVE-2025-59203

5.5MEDIUM

What is CVE-2025-59203?

The Windows StateRepository API contains a vulnerability that permits authorized attackers to inadvertently insert sensitive information into log files. This flaw can lead to unauthorized local disclosure of sensitive data, exposing critical information that may be exploited for further attacks. To mitigate risks, users are advised to monitor their systems for any unusual log activities and apply best practices for security hygiene.

Affected Version(s)

Windows 10 Version 1507 32-bit Systems 10.0.10240.0 < 10.0.10240.21161

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.8519

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.7919

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59203 : Sensitive Information Disclosure in Windows StateRepository API by Microsoft