Описание
Microsoft Failover Cluster Information Disclosure Vulnerability
Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally.
FAQ
What type of information could be disclosed by this vulnerability?
An attacker that successfully exploited this vulnerability could recover any data that is put in the system logs on the Compute Instance including cleartext passwords.
What further actions should I take to protect my environment after applying the fix?
Even after applying the security update, residual sensitive information may still exist in system logs. We strongly recommend that administrator users change their passwords to mitigate any potential risk from previously exposed credentials.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| Windows Server 2022, 23H2 Edition (Server Core installation) | ||
| Windows Server 2025 | ||
| Windows Server 2025 (Server Core installation) |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally.
Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally.
EPSS
5.5 Medium
CVSS3