Microsoft Windows ETL Channel Information Disclosure Vulnerability

Vulnerability

A vulnerability exists in the Windows ETL Channel that allows an authorized attacker to locally disclose sensitive information by inserting it into a log file. This issue affects multiple Windows products and versions.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure, specifically local memory addresses.

Remediation

Users can download the security update for this vulnerability via the Microsoft Update Catalog. Security Update KB5066836 is available for Windows Server 2016, Windows 10 Version 1607, Windows Server 2025, Windows 11 Version 24H2, and several other Windows 10 and Windows Server versions. For Windows 11 Version 23H2, the security update KB5066793 is available. Windows Server 2022 also has a security update available. Consult the Microsoft Update Catalog for the specific update needed.

Added: Oct 14, 2025, 6:47 PM
Updated: Oct 14, 2025, 9:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
0.0
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.