MSRC compact vulnerability detail

CVE-2025-48823 · Windows Cryptographic Services Information Disclosure Vulnerability

Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a network.

Severity
Important
Impact
Information Disclosure
CVSS
5.9 base · 5.2 temporal
Release
2025-07-08
Signals
Windows Cryptographic Services Information Disclosure Exploited: No Publicly disclosed: No Exploitability: Exploitation Less Likely
CWE
Patch Diff
Loading module diff metadata...
Resolved binary override
Use this when the MSRC module name cannot be mapped automatically or the resolved binary looks wrong.
Old version New version
Description
Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a network.
FAQ / Articles
Windows Cryptographic Services Elevation of Privilege Vulnerability
Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges over a network.
Windows Cryptographic Services Information Disclosure Vulnerability
Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a network.
FAQ
According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability To exploit this vulnerability, an attacker would need to target an application by persisting encrypted secrets that are using specific old cryptography and Windows APIs.
FAQ
What type of information could be disclosed by this vulnerability If the attacker has both the ability to modify the encrypted secret where it is stored and to observe the precise timing for the secret being decrypted by the application, the attacker could infer the original secret across many decryption attempts.