Description
Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply patch
AI Analysis

Impact

A pointer dereference flaw in Windows Failover Cluster allows an attacker who can send traffic to the cluster to execute arbitrary code with the privileges of the cluster service. The vulnerability permits the execution of malicious code without authenticating a user, potentially compromising system confidentiality, integrity, and availability.

Affected Systems

The flaw affects Microsoft Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025, and Windows Server 2025 (Server Core installation). No additional affected‑version information is supplied beyond these product releases.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity. No EPSS data is available, so the probability of exploitation cannot be quantified from this entry. The issue is not listed in the CISA KEV catalog, suggesting no far‑relied public exploitation yet. The likely attack vector is through network traffic that targets the Failover Cluster service, and an attacker must have network reach to a cluster node to trigger the untrusted pointer dereference.

Generated by OpenCVE AI on September 9, 2026 at 02:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft security update for CVE-2026-78444 from the MSRC update guide.
  • Restrict network access to Failover Cluster nodes using firewall or segmentation so that only trusted management traffic can reach the cluster service.
  • If the Failover Cluster feature is not required, disable or remove it from the system to eliminate the attack surface.

Generated by OpenCVE AI on September 9, 2026 at 02:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows Server 2019 (server Core Installation)
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows Server 2019 (server Core Installation)
Microsoft windows Server 2025 (server Core Installation)

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.
Title Microsoft Failover Cluster Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1809
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-822
CPEs cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1809
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1809 Windows Server 2019 Windows Server 2019 (server Core Installation) Windows Server 2022 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:38:08.919Z

Reserved: 2026-08-24T16:21:50.286Z

Link: CVE-2026-78444

cve-icon Vulnrichment

Updated: 2026-09-11T20:44:34.830Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:42.133

Modified: 2026-09-11T21:17:16.287

Link: CVE-2026-78444

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:48:54Z

Weaknesses
  • CWE-822

    Untrusted Pointer Dereference