CyberICT

CVE-2026-41095

Microsoft · Published May 12, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Data Deduplication Elevation of Privilege Vulnerability. Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally.

Affected Products

  • Windows Server 2025 (Server Core installation)
  • Windows Server 2019 (Server Core installation)
  • Windows Server 2022, 23H2 Edition (Server Core installation)
  • Windows Server 2025

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C