Junglewise Threat Intelligence

CVE-2026-50357: Microsoft Windows ReFS numeric truncation code execution

CVE-2026-50357 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Resilient File System (ReFS), a component used to manage and protect large amounts of data on Windows systems. An attacker who already has basic access to a computer could exploit this flaw to run malicious code with elevated permissions. This could lead to a full system takeover, allowing the attacker to steal sensitive data or disrupt business operations.

Technical details

A numeric truncation error (CWE-197) exists within the Windows Resilient File System (ReFS) driver. The vulnerability is triggered when the system incorrectly handles integer conversions, potentially leading to memory corruption. An attacker with low-privileged local access can exploit this flaw to execute arbitrary code in the context of the kernel or a highly privileged service. The attack requires no user interaction and has a high impact on confidentiality, integrity, and availability. Microsoft has released security updates to address this issue across affected Windows 10, 11, and Server versions.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2016 All versions

Timeline

  • 2026-07-14: disclosed: Vulnerability published by Microsoft and NVD
  • 2026-07-14: patched: Security updates made available via Microsoft Security Update Guide

References

Related threats