Junglewise Threat Intelligence

CVE-2026-49793: Microsoft Windows ReFS heap buffer overflow

CVE-2026-49793 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Windows Resilient File System (ReFS), a component used to manage and protect large amounts of data on Windows systems. An attacker who already has basic access to a computer could exploit this flaw to gain higher-level control and execute malicious code. This could lead to a full system compromise, allowing the attacker to view sensitive data, modify files, or disrupt operations.

Technical details

This vulnerability is a heap-based buffer overflow (CWE-122) located within the Windows Resilient File System (ReFS) driver. The flaw is triggered when the system improperly handles memory allocation during file system operations. An attacker must have local access to the target system and be authenticated with low-level privileges to exploit the vulnerability. Successful exploitation allows for local privilege escalation and arbitrary code execution in the context of the kernel or a highly privileged service. Microsoft has released security updates to address this issue across affected versions of Windows 10, Windows 11, and Windows Server.

Affected products

  • Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 Versions 24H2, 25H2, 26H1
  • Microsoft Windows Server 2016 Standard and Server Core installations

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats