Executive brief
A security vulnerability exists in the Windows Data Deduplication feature, which is used to optimize storage space by removing duplicate data. An attacker who already has basic access to a system could exploit this flaw to gain full administrative control. This could lead to the theft of sensitive data, installation of malicious software, or disruption of business operations.
Technical details
A use-after-free vulnerability (CWE-416) exists within the Microsoft Windows Data Deduplication service. The flaw is triggered when the system continues to use a memory pointer after it has been freed, leading to memory corruption. An attacker with local access and low-level privileges can exploit this condition to execute arbitrary code with elevated system permissions. The attack requires no user interaction and has a low complexity, though it does require prior authenticated access to the target machine. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows Data Deduplication
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory