Impact
The flaw is a double free bug in the Windows Failover Cluster service that allows a local user with authorized access to the cluster configuration to gain elevated local privileges. Exploiting the vulnerability can run code or perform actions with higher authority than the original user. The impact is confined to the host where the bug occurs; there is no remote code execution or denial of service reported.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 1607 and 1809 and all Microsoft Windows Server releases from 2012 through 2025, including Server Core installations where the Failover Cluster role is present.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, and the EPSS score of less than 1% indicates a low likelihood of exploitation. The vulnerability is not yet included in the CISA KEV catalog, suggesting it has not been widely leveraged by threat actors. Based on the description, it is inferred that the attacker must have authorized access to the cluster configuration to trigger the double free. If the attacker already has a local account that can manage the cluster, elevation of local privileges on the compromised host is possible.
OpenCVE Enrichment