Impact
The vulnerability originates from a use of an uninitialized resource within the Windows Failover Cluster component. An attacker who can reach the cluster service over a network can trigger the flaw and retrieve sensitive information that the cluster processes, leading to a breach of data confidentiality. The weakness falls under CWE‑908 (Information Exposure) and does not provide a direct execution path, but it allows disclosure of internal values that could assist in further attacks.
Affected Systems
Affected are Microsoft Windows 10 Version 1809, Windows Server 2019 (including Server Core installation), Windows Server 2022, Windows Server 2025, and Windows Server 2025 Server Core installation. These systems contain the vulnerable cluster component and do not appear to have a patch yet listed in the provided data.
Risk and Exploitability
This vulnerability has a CVSS score of 7.5, indicating high severity. EPSS is not available, so the current estimation of exploitation probability cannot be inferred. The vulnerability is not listed in the CISA KEV catalog, meaning known exploitation is not yet reported. The likely attack vector is a remote network connection to the Failover Cluster service, inferred from the description, and the attacker must be able to communicate with the cluster node to trigger the uninitialized use and extract data.
OpenCVE Enrichment