CyberICT

CVE-2026-23672

Microsoft · Published March 10, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability. What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

Affected Products

  • Windows Server 2022 (Server Core installation)
  • Windows Server 2022
  • Windows Server 2019 (Server Core installation)
  • Windows 10 Version 21H2 for ARM64-based Systems

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C