Microsoft Windows High Availability Services Information Disclosure Vulnerability

Vulnerability

A vulnerability in Windows High Availability Services allows an authorized attacker to locally disclose sensitive information. This issue arises from the exposure of certain memory addresses within kernel space, which could potentially be leveraged for malicious activities.

Impact

Exploitation of this vulnerability could lead to unauthorized disclosure of sensitive information, specifically certain memory addresses within kernel space.

Remediation

Users can download the security update for this vulnerability via the Microsoft Update Catalog. Security Update KB5066836 is available for Windows Server 2016, Windows Server 2025, Windows Server 2022 (23H2 Edition), and Windows Server 2019. For Windows Server 2022 (Server Core installation), the security update KB5066780 can be downloaded from the Microsoft Update Catalog.

Added: Oct 14, 2025, 7:11 PM
Updated: Oct 14, 2025, 9:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
0.0
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.