ID:12489 - Exploit for Information disclosure in Windows and Windows Server - CVE-2025-59284

 
Main Vulnerability Database Exploits ID:12489 - Exploit for Information disclosure in Windows and Windows Server - CVE-2025-59284

ID:12489 - Exploit for Information disclosure in Windows and Windows Server - CVE-2025-59284

Published: March 13, 2026


Vulnerability identifier: #VU117235
Vulnerability risk: Medium
CVE-ID: CVE-2025-59284
CWE-ID: CWE-200
Exploitation vector: Remote access
Vulnerable software:
Windows
Windows Server

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to user's credentials can be leaked when parsing hard links inside .tar archives. A remote attacker can trick the victim into opening a specially crafted .tar archive and force the system to relay NTLM credentials via an outgoing SMB request. 


Remediation

Install updates from vendor's website.