Microsoft Windows Cryptographic Services Information Disclosure Vulnerability

Vulnerability

A vulnerability exists in Windows Cryptographic Services due to the use of a cryptographic primitive with a risky implementation. This flaw allows an authorized attacker to locally disclose information by reading small portions of heap memory.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure.

Remediation

Users can apply the security update KB5055526 to address this vulnerability. This update is available through the Microsoft Update Catalog.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
2.5
exploitability
3.5
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.