ZeroHour

CVE-2026-72989

large

Uninitialized Resource Information Disclosure in Windows Failover Cluster

CVSS 3.1
7.5 high
EPSS
<1%p54
Published
()
Modified
AI analysis

Windows Failover Cluster contains a use-of-uninitialized-resource flaw (CWE-908) that can be reached over the network by an unauthorized attacker who does not need valid credentials or user interaction. An attacker who sends malicious input to the cluster service can cause the software to return memory that was never initialized, leaking its contents. The impact is limited to confidential information disclosure; the flaw does not allow tampering or denial of service per the CVSS score (C:H/I:N/A:N). Any organization running Windows Server with the Failover Clustering feature enabled is potentially affected, most plausibly on networks where the cluster service is reachable by untrusted clients. As of now there is no known exploitation in the wild, no public proof-of-concept, the issue is not in CISA KEV, and EPSS assigns a modest 0.8% probability of exploitation within 30 days.

What to do: Identify Windows Server hosts with the Failover Clustering feature enabled and prioritize applying Microsoft's security update as soon as it is available; note that the source data does not specify affected versions or patch KBs, so track the Microsoft advisory for those details. In the meantime, restrict network access to cluster nodes and cluster management/service endpoints so only trusted networks and administrators can reach them, since the flaw requires network reachability but no authentication. Monitor for updates from Microsoft and re-assess priority if a PoC, KEV listing, or in-the-wild exploitation appears.

Affected
Microsoft Windows Failover Cluster (Failover Clustering feature on Windows Server)
Estimated exposure
largelikely on the order of hundreds of thousands of Windows Server cluster nodes worldwide (estimate; internet-exposed instances likely far fewer) — Failover Clustering is a widely used high-availability feature in enterprise Windows Server deployments (Hyper-V, SQL Server, file services), suggesting roughly 10^5 nodes globally, but these are typically internal rather than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network.

Weakness
CWE-908
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.