CVE-2025-47979: Microsoft Failover Cluster Information Disclosure Vulnerability

Overview

Severity
Medium (CVSS 5.5)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Category
Information Disclosure
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2025-Oct
Released
2025-10-14
EPSS Score
0.07% (percentile: 21.7%)

Description

Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally.

FAQ

What type of information could be disclosed by this vulnerability? An attacker that successfully exploited this vulnerability could recover any data that is put in the system logs on the Compute Instance including cleartext passwords. What further actions should I take to protect my environment after applying the fix? Even after applying the security update, residual sensitive information may still exist in system logs. We strongly recommend that administrator users change their passwords to mitigate any potential risk from previously exposed credentials.

Affected Products (3)

Windows

  • Windows Server 2025 (Server Core installation)
  • Windows Server 2022, 23H2 Edition (Server Core installation)
  • Windows Server 2025

Security Updates (2)

Acknowledgments

Anonymous

Revision History

  • 2025-10-14: Information published.