CVE-2025-47979 is a medium-severity vulnerability affecting Microsoft Windows Server 2022 23H2 and Windows Server 2025, where sensitive information is improperly inserted into log files within Windows Failover Cluster. An authorized local attacker can exploit this with low complexity to achieve high confidentiality impact by disclosing sensitive data. While not actively exploited or listed in KEV, the vulnerability has garnered significant community and media attention, with no public exploit code currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.25398.1913CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:* | ||
<= 10.0.26100.6899CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.