Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
High

Windows Cluster Client Failover Use-After-Free Elevation of Privilege

IdentifiersCVE-2026-21251CWE-416· Use After Free

CVE-2026-21251 is a local elevation-of-privilege vulnerability in the Windows Cluster Client Failover (CCF) component caused by a use-after-free memory corruption flaw. The issue arises from improper memory management in cluster failover handling, where a freed object can remain referenced through a dangling pointer and later be dereferenced. The provided content states that an attacker with authorized local access can trigger cluster failover operations, reclaim the freed memory with attacker-controlled data, and hijack execution flow. Affected products listed in the content include Windows Server 2016, 2019, 2022, 2022 23H2, and 2025.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an authorized local attacker to elevate privileges on the affected Windows Server system, potentially to SYSTEM level. The content indicates this can result in compromise of confidentiality, integrity, and availability on the host, including full control over the local system in the context of the elevated account.

Mitigation

If you can’t patch tonight, do this now.

Where immediate patching is not possible, restrict local access to systems running cluster services to essential personnel only, enforce least privilege, enable protections such as Credential Guard, and disable the Cluster Service on systems where clustering is not required. The content specifically references disabling the service with commands such as 'sc.exe config ClusSvc start= disabled' and stopping it with 'sc.exe stop ClusSvc' when appropriate.

Remediation

Patch, then assume compromise.

Apply Microsoft's security updates for CVE-2026-21251 to all affected and supported Windows Server versions. The content specifically states that Microsoft has released patches and recommends prompt installation and verification of successful deployment.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Microsoft CorporationWindows Server 2016operating_system
Microsoft CorporationWindows Server 2019operating_system
Microsoft CorporationWindows Server 2022operating_system
Microsoft CorporationWindows Server 2022 23h2operating_system
Microsoft CorporationWindows Server 2025operating_system
Microsoft CorporationWindows Server 23h2operating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity3

Community discussion across Reddit, Mastodon, and other social sources.