CVE-2025-29809
Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RC:C
- EPSS probability
- 4.17%
- CWE
- CWE-922
- Published
- 2025-04-08
- Last modified
- 2026-08-10
Affected products
- Microsoft Windows 10 Version 1507
- Microsoft Windows 10 Version 1607
- Microsoft Windows 10 Version 1809
- Microsoft Windows 10 Version 21H2
- Microsoft Windows 10 Version 22H2
- Microsoft Windows 11 version 22H2
- Microsoft Windows 11 version 22H3
- Microsoft Windows 11 Version 23H2
Weakness type
Related vulnerabilities
- CVE-2024-7569 — An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows a
- CVE-2023-32191 — rke's credentials are stored in the RKE1 Cluster state ConfigMap
- CVE-2022-0724 — Insecure Storage of Sensitive Information in microweber/microweber
- CVE-2024-3501 — Exposure of Sensitive Information in lunary-ai/lunary
- CVE-2024-10943 — FactoryTalk® Updater Authentication Bypass
- CVE-2025-10971 — Insecure Storage of Sensitive Information
- CVE-2023-43634 — Config Partition Not Protected by Measured Boot
- CVE-2023-43633 — Debug Functions Unlockable Without Triggering Measured Boot