Junglewise Threat Intelligence

CVE-2026-71338: Microsoft Windows Failover Cluster double free privilege escalation

CVE-2026-71338 · Severity: medium · CVSS 6.4 · Published 2026-09-08

Executive brief

Windows Failover Cluster is a Microsoft system component that manages clusters of servers for high availability. A double-free memory vulnerability allows an authorized local user to escalate their privileges on the system, potentially gaining administrative access without proper authorization.

Technical details

A double-free vulnerability exists in Windows Failover Cluster where memory is freed twice in certain code paths, potentially leading to heap corruption and code execution. The vulnerability requires prior authentication/authorization to trigger, as it can only be exploited by an authorized local attacker with existing access to the system. The attack vector is local; it does not require network access. Successful exploitation allows privilege escalation from the attacker's current user context to a higher privilege level. Microsoft has issued a security patch to resolve this issue.

Affected products

  • Microsoft Windows Failover Cluster <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats