Information Disclosure
The latest Information Disclosure coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft Patches DWM Bug CVE-2026-20805 That Leaks Sensitive Data on Windows
Microsoft has released security updates to fix a Desktop Window Manager (DWM) vulnerability that could allow an attacker with local access to read sensitive information from Windows PCs. Tracked as...
CVE-2026-20962: Windows DRTM Security Flaw Exposes Local Information Disclosure Risk
Microsoft has disclosed a significant security vulnerability in Windows systems that could allow local attackers to access sensitive information through an uninitialized resource flaw in the Dynamic...
Linux Kernel USB Storage Vulnerability CVE-2025-68288: Analysis, Impact, and Fix
A newly disclosed Linux kernel vulnerability, tracked as CVE-2025-68288, has revealed a subtle but significant memory leak in the USB mass-storage transport path that could allow USB protocol bytes...
CVE-2025-62570: Microsoft Fixes High-Risk Windows Camera Information Leak
On December 9, Microsoft rolled out its final Patch Tuesday of 2025, and one fix stands out for its potential to disarm a stealthy attacker: CVE-2025-62570, an information disclosure vulnerability in...
Microsoft Warns of Windows DirectX Memory Leak: Patch Now to Block Attacks
Microsoft has acknowledged a new information-disclosure vulnerability in the Windows DirectX graphics component that could let attackers read sensitive data from a system’s memory. The flaw, tagged...
CVE-2025-62473: Critical Windows RRAS Buffer Over-Read Vulnerability Explained
Microsoft has disclosed a significant security vulnerability in the Windows Routing and Remote Access Service (RRAS), tracked as CVE-2025-62473, which could allow attackers to remotely read sensitive...
Libvirt Security Flaw CVE-2025-13193 Exposes VM Snapshots: Critical Vulnerability Analysis
A critical security vulnerability in libvirt, the popular open-source virtualization management library, has been discovered that exposes sensitive virtual machine data through improperly secured...
CVE-2025-60728: Excel Information Disclosure Vulnerability Analysis
Microsoft has disclosed a significant security vulnerability in Excel tracked as CVE-2025-60728, classified as an information disclosure flaw stemming from an untrusted pointer dereference. This...
Windows License Manager Log Bug Exposes Secrets – Patch Now to Stop Local Reconnaissance
Microsoft has quietly patched an information disclosure flaw in the Windows License Manager that could hand local attackers a map of your network's secrets—all from reading log files meant for...
Windows License Manager Bug Exposes System Secrets—Patch Issued for CVE-2025-62209
Microsoft has shipped a security fix for CVE‑2025‑62209, a local information‑disclosure vulnerability in the Windows License Manager that could let attackers harvest sensitive system artifacts...
CVE-2025-59240: Excel Information Disclosure Vulnerability Patched
Microsoft has addressed a critical information disclosure vulnerability in Excel tracked as CVE-2025-59240, which could allow attackers to access sensitive local data through specially crafted...
CVE-2025-62206: Critical Dynamics 365 On-Premises Vulnerability Requires Immediate Patching
Microsoft has issued a critical security advisory for CVE-2025-62206, a significant information disclosure vulnerability affecting Microsoft Dynamics 365 (On-Premises) deployments. This...