VDB
CISA-2025-59214
CISA-2025-59214
PUBLISHED
CVSS 6.5 MEDIUM
Reported by microsoft · Published October 14, 2025
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 10 Version 1507 | 10.0.10240.0 |
| Microsoft | Windows 10 Version 1607 | 10.0.14393.0 |
| Microsoft | Windows 10 Version 1809 | 10.0.17763.0 |
| Microsoft | Windows 10 Version 21H2 | 10.0.19044.0 |
| Microsoft | Windows 10 Version 22H2 | 10.0.19045.0 |
| Microsoft | Windows 11 version 22H2 | 10.0.22621.0 |
| Microsoft | Windows 11 version 22H3 | 10.0.22631.0 |
| Microsoft | Windows 11 Version 23H2 | 10.0.22631.0 |
| Microsoft | Windows 11 Version 24H2 | 10.0.26100.0 |
| Microsoft | Windows 11 Version 25H2 | 10.0.26200.0 |
| Microsoft | Windows Server 2008 R2 Service Pack 1 | 6.1.7601.0 |
| Microsoft | Windows Server 2008 R2 Service Pack 1 (Server Core installation) | 6.1.7601.0 |
| Microsoft | Windows Server 2008 Service Pack 2 | 6.0.6003.0 |
| Microsoft | Windows Server 2008 Service Pack 2 (Server Core installation) | 6.0.6003.0 |
| Microsoft | Windows Server 2012 | 6.2.9200.0 |
| Microsoft | Windows Server 2012 (Server Core installation) | 6.2.9200.0 |
| Microsoft | Windows Server 2012 R2 | 6.3.9600.0 |
| Microsoft | Windows Server 2012 R2 (Server Core installation) | 6.3.9600.0 |
| Microsoft | Windows Server 2016 | 10.0.14393.0 |
| Microsoft | Windows Server 2016 (Server Core installation) | 10.0.14393.0 |
…and 50 more
Timeline
- Oct 14, 2025 CVE Published
- Feb 22, 2026 CVE Updated
- Mar 28, 2026 Security Advisory
References
- Microsoft Windows File Explorer Spoofing Vulnerability vendor-advisorypatch
- https://github.com/rubenformation/CVE-2025-50154/ url
- https://cymulate.com/blog/ntlm-leak-cve-2025-59214/ url
- https://www.vicarius.io/vsociety/posts/cve-2025-59214-detection-script-windows-file-explorer-spoofing-vulnerability url
- https://www.vicarius.io/vsociety/posts/cve-2025-59214-mitigation-script-windows-file-explorer-spoofing-vulnerability url