CVE-2025-59258: Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability
Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally.
Other sources
Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59258?
CVE-2025-59258 is classified as an information disclosure vulnerability that could allow unauthorized access to sensitive information in log files.
How do I fix CVE-2025-59258?
To fix CVE-2025-59258, apply the latest patches provided by Microsoft for the affected Windows Server versions.
Which Windows Server versions are affected by CVE-2025-59258?
CVE-2025-59258 affects multiple versions of Windows Server, including 2012, 2016, 2019, 2022, and 2025.
What kind of information can be disclosed due to CVE-2025-59258?
CVE-2025-59258 may lead to the unauthorized disclosure of sensitive information contained in Active Directory Federation Services log files.
How can I determine if I am vulnerable to CVE-2025-59258?
You can determine vulnerability to CVE-2025-59258 by checking if your installation of Windows Server is among those affected and if you have applied the necessary security patches.