Microsoft HPC Pack Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability exists in Microsoft High Performance Compute (HPC) Pack) 2016 and 2019. This vulnerability allows an attacker with access to the same network as the targeted clusters or nodes to send a specially crafted HTTPS request to the head node or a Linux compute node, potentially leading to unauthorized code execution on other connected clusters or nodes.

Impact

Exploitation of this vulnerability allows for remote code execution on the affected head node or Linux compute node, with the potential to execute code on other clusters or nodes connected to the targeted head node.

Remediation

Users can apply the security update available through the Microsoft Update Catalog. Instructions for downloading this update can be found in the release notes for HPC Pack 2016 Update 3 and HPC Pack 2019 Update 3.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
3.5
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.