Impact
A pointer dereference flaw in Windows Failover Cluster allows an attacker who can send traffic to the cluster to execute arbitrary code with the privileges of the cluster service. The vulnerability permits the execution of malicious code without authenticating a user, potentially compromising system confidentiality, integrity, and availability.
Affected Systems
The flaw affects Microsoft Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025, and Windows Server 2025 (Server Core installation). No additional affected‑version information is supplied beyond these product releases.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. No EPSS data is available, so the probability of exploitation cannot be quantified from this entry. The issue is not listed in the CISA KEV catalog, suggesting no far‑relied public exploitation yet. The likely attack vector is through network traffic that targets the Failover Cluster service, and an attacker must have network reach to a cluster node to trigger the untrusted pointer dereference.
OpenCVE Enrichment