Microsoft Windows Kernel Information Disclosure Vulnerability

Vulnerability

A vulnerability in the Windows Kernel has been identified, allowing authorized attackers to locally disclose sensitive information. This issue arises from the generation of error messages that contain private data, specifically certain memory addresses within kernel space. Knowledge of these memory locations could potentially be exploited for malicious purposes.

Impact

Exploitation of this vulnerability could lead to unauthorized disclosure of sensitive information, specifically memory addresses within kernel space, which could be leveraged for further malicious activities.

Remediation

Users can download the security update for this vulnerability through the Microsoft Update Catalog. For Windows Server 2012 R2, Windows Server 2016, and Windows 10 Version 1607, the security update is available as part of the monthly rollup. Knowledge base articles for these versions provide additional information.

Added: Sep 9, 2025, 6:51 PM
Updated: Sep 9, 2025, 6:51 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.