CVE-2026-41095
Microsoft · Published May 12, 2026
7.8
CVSS v3.1
HIGHPatch availableGet patch
Description
Data Deduplication Elevation of Privilege Vulnerability. Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally.
Affected Products
- Windows Server 2025 (Server Core installation)
- Windows Server 2019 (Server Core installation)
- Windows Server 2022, 23H2 Edition (Server Core installation)
- Windows Server 2025
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C