CVE-2026-72989
largeUninitialized Resource Information Disclosure in Windows Failover Cluster
Windows Failover Cluster contains a use-of-uninitialized-resource flaw (CWE-908) that can be reached over the network by an unauthorized attacker who does not need valid credentials or user interaction. An attacker who sends malicious input to the cluster service can cause the software to return memory that was never initialized, leaking its contents. The impact is limited to confidential information disclosure; the flaw does not allow tampering or denial of service per the CVSS score (C:H/I:N/A:N). Any organization running Windows Server with the Failover Clustering feature enabled is potentially affected, most plausibly on networks where the cluster service is reachable by untrusted clients. As of now there is no known exploitation in the wild, no public proof-of-concept, the issue is not in CISA KEV, and EPSS assigns a modest 0.8% probability of exploitation within 30 days.
What to do: Identify Windows Server hosts with the Failover Clustering feature enabled and prioritize applying Microsoft's security update as soon as it is available; note that the source data does not specify affected versions or patch KBs, so track the Microsoft advisory for those details. In the meantime, restrict network access to cluster nodes and cluster management/service endpoints so only trusted networks and administrators can reach them, since the flaw requires network reachability but no authentication. Monitor for updates from Microsoft and re-assess priority if a PoC, KEV listing, or in-the-wild exploitation appears.
| Microsoft Windows Failover Cluster (Failover Clustering feature on Windows Server) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network.
- Weakness
- CWE-908
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.