Description
Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 7.5 High
EPSS: 1.0% Low
KEV: No
Impact: Information Disclosure via Network
Action: Apply Patch
AI Analysis

Impact

The vulnerability originates from a use of an uninitialized resource within the Windows Failover Cluster component. An attacker who can reach the cluster service over a network can trigger the flaw and retrieve sensitive information that the cluster processes, leading to a breach of data confidentiality. The weakness falls under CWE‑908 (Information Exposure) and does not provide a direct execution path, but it allows disclosure of internal values that could assist in further attacks.

Affected Systems

Affected are Microsoft Windows 10 Version 1809, Windows Server 2019 (including Server Core installation), Windows Server 2022, Windows Server 2025, and Windows Server 2025 Server Core installation. These systems contain the vulnerable cluster component and do not appear to have a patch yet listed in the provided data.

Risk and Exploitability

This vulnerability has a CVSS score of 7.5, indicating high severity. EPSS is not available, so the current estimation of exploitation probability cannot be inferred. The vulnerability is not listed in the CISA KEV catalog, meaning known exploitation is not yet reported. The likely attack vector is a remote network connection to the Failover Cluster service, inferred from the description, and the attacker must be able to communicate with the cluster node to trigger the uninitialized use and extract data.

Generated by OpenCVE AI on September 9, 2026 at 01:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest security update from Microsoft that addresses the uninitialized resource issue in Windows Failover Cluster.
  • Restrict network traffic to the Failover Cluster service by configuring firewall rules to allow only trusted networks and authorized hosts.
  • Verify that cluster nodes restrict management ports and enforce proper authentication; disabling or limiting unnecessary clustering endpoints can reduce exposure.

Generated by OpenCVE AI on September 9, 2026 at 01:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*

Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows Server 2019 (server Core Installation)
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows Server 2019 (server Core Installation)
Microsoft windows Server 2025 (server Core Installation)

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network.
Title Windows Failover Cluster Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1809
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-908
CPEs cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1809
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1809 Windows Server 2019 Windows Server 2019 (server Core Installation) Windows Server 2022 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:37:36.901Z

Reserved: 2026-08-10T18:38:17.057Z

Link: CVE-2026-72989

cve-icon Vulnrichment

Updated: 2026-09-08T20:05:03.524Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:26.373

Modified: 2026-09-21T15:33:38.630

Link: CVE-2026-72989

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T21:15:13Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource