CVE-2026-73010
9.8Microsoft · Windows Failover Cluster
A use after free vulnerability in the Windows Failover Cluster component allows an unauthenticated remote attacker to execute arbitrary code.
Executive summary
A critical use after free vulnerability in Windows Failover Cluster enables unauthenticated remote code execution, posing an immediate risk to system integrity and availability.
Vulnerability
This is a use after free flaw (CWE-416) within the Windows Failover Cluster service that can be triggered by an unauthenticated attacker over the network to achieve remote code execution.
Business impact
Successful exploitation grants an attacker full control over the affected Windows system, leading to complete compromise of sensitive data, unauthorized system access, and potential lateral movement within the network. With a CVSS score of 9.8, this vulnerability represents a critical risk that could lead to significant operational disruption and data breaches.
Remediation
Immediate Action: Apply the security updates provided by Microsoft to reach the fixed build versions (e.g., 10.0.17763.9245 for Windows 10 Version 1809 and Server 2019) as specified in the official MSRC update guide.
Proactive Monitoring: Review system and cluster logs for anomalous network traffic or unexpected process execution originating from the Failover Cluster service.
Compensating Controls: Restrict network access to the Failover Cluster management ports to trusted administrative segments via host-based firewalls or network access control lists until patches are deployed.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical CVSS severity and the ability for an unauthenticated attacker to execute code remotely, this vulnerability must be prioritized for immediate remediation. Organizations should audit their environments to identify all instances of the affected Windows versions and apply the corresponding security patches without delay.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
- Microsoft Failover Cluster Remote Code Execution Vulnerability Vendor advisory