Microsoft Windows Failover Cluster Information Disclosure Vulnerability

Vulnerability

A vulnerability exists in Windows Failover Cluster that allows an authorized attacker to locally disclose sensitive information by inserting it into a log file. This issue affects several versions of Windows Server 2025 and Windows Server 2022, 23H2 Edition (Server Core installation).

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure, including cleartext passwords, from system logs on the affected server.

Remediation

Users can apply the security update available through the Microsoft Update Catalog. After applying the update, it is recommended to change passwords to mitigate any risks from previously exposed credentials.

Added: Oct 14, 2025, 5:28 PM
Updated: Oct 14, 2025, 10:10 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
2.5
exploitability
3.5
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.