Executive brief
A security vulnerability exists in the Windows Resilient File System (ReFS), a component used to manage and protect large amounts of data on Windows systems. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the device. This could allow them to access restricted files, install malicious software, or disrupt business operations.
Technical details
A stack-based buffer overflow (CWE-121) exists in the Windows Resilient File System (ReFS) driver. The vulnerability is triggered when the driver improperly handles specific file system operations, allowing a local attacker with low-level privileges to overwrite memory on the system stack. By successfully exploiting this flaw, an attacker can execute arbitrary code with SYSTEM privileges. The attack requires local access to the target machine but no user interaction. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2016 Standard and Server Core
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory