Executive brief
A security vulnerability exists in the Windows Resilient File System (ReFS), a component used to manage and protect large amounts of data on Windows servers and workstations. An attacker who successfully exploits this flaw could gain the ability to run malicious code on the affected system. While the attack requires local access or user interaction, it could lead to a complete compromise of the machine, including data theft or system disruption.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists within the Windows Resilient File System (ReFS) driver. The flaw is triggered when the system processes specially crafted file system metadata, leading to memory corruption. Although the attack vector is classified as local, the CVSS vector indicates that user interaction is required, suggesting an attacker might need to entice a user to mount a malicious ReFS volume or open a crafted file. Successful exploitation allows for arbitrary code execution with the privileges of the ReFS driver, typically resulting in full system compromise. Microsoft has released security updates to address this issue across supported versions of Windows 10, 11, and Windows Server.
Affected products
- Microsoft Windows 10 Version 1607 / 1809 / 21H2 / 22H2 Multiple versions prior to July 2026 updates
- Microsoft Windows 11 Version 24H2 / 25H2 / 26H1 Multiple versions prior to July 2026 updates
- Microsoft Windows Server 2016 / 2019 / 2022 / 2025 Multiple versions prior to July 2026 updates
Timeline
- 2026-07-14: disclosed: Initial disclosure by Microsoft and NVD
- 2026-07-14: advisory: Microsoft Security Update Guide published