CVE Vulnerabilities

CVE-2025-59258

Insertion of Sensitive Information into Log File

Published: Oct 14, 2025 | Modified: Oct 20, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Windows_server_2012 Microsoft - (including) - (including)
Windows_server_2012 Microsoft r2 (including) r2 (including)
Windows_server_2016 Microsoft * 10.0.14393.8519 (including)
Windows_server_2019 Microsoft * 10.0.17763.7919 (excluding)
Windows_server_2022 Microsoft * 10.0.20348.4294 (excluding)
Windows_server_2022_23h2 Microsoft * 10.0.25398.1913 (excluding)
Windows_server_2025 Microsoft * 10.0.26100.6899 (including)

Potential Mitigations

References