Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally.
What type of information could be disclosed by this vulnerability? An attacker that successfully exploited this vulnerability could recover any data that is put in the system logs on the Compute Instance including cleartext passwords. What further actions should I take to protect my environment after applying the fix? Even after applying the security update, residual sensitive information may still exist in system logs. We strongly recommend that administrator users change their passwords to mitigate any potential risk from previously exposed credentials.
Anonymous