Microsoft Windows Kernel Information Disclosure Vulnerability

Vulnerability

A vulnerability in the Windows Kernel allows an authorized attacker to locally disclose sensitive information. This issue could potentially be exploited to reveal certain memory addresses within kernel space, which an attacker might leverage for malicious activities.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure, specifically revealing sensitive memory addresses within the kernel, potentially facilitating further attacks.

Remediation

Users can download the security update for this vulnerability via the Microsoft Update Catalog. Security update KB5066836 is available for Windows Server 2016 and Windows Server 2019. For Windows Server 2022, the security update is part of the 23H2 edition (Server Core installation). Windows Server 2025 and its Server Core installation also have this update available. Users can refer to the respective Knowledge Base articles for more information.

Added: Oct 14, 2025, 7:50 PM
Updated: Oct 14, 2025, 7:50 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
0.0
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.