Microsoft Windows Cryptographic Services Information Disclosure Vulnerability

Vulnerability

A vulnerability exists in Windows Cryptographic Services due to the use of a cryptographic primitive with a risky implementation. This flaw allows an authorized attacker to locally disclose information, potentially including secrets or privileged data belonging to the user of the affected application.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure.

Remediation

Users can download the security update for this vulnerability via the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles KB5066835, KB5066791, KB5066780, KB5066586, and KB5066782.

Added: Oct 14, 2025, 7:31 PM
Updated: Oct 14, 2025, 9:51 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.