Executive brief
A security vulnerability exists in the Windows Resilient File System (ReFS), a component used to manage and protect large amounts of data on Windows systems. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to access sensitive files, install malicious software, or disrupt business operations.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists within the Windows Resilient File System (ReFS) driver. The flaw is triggered when the system improperly handles memory allocation during file system operations. An attacker with low-privileged local access can exploit this by sending specially crafted requests to the ReFS driver, leading to memory corruption. Successful exploitation allows the attacker to execute arbitrary code with SYSTEM privileges. Microsoft has released security updates to address this issue across affected versions of Windows 10, Windows 11, and Windows Server.
Affected products
- Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 Versions 24H2, 25H2, 26H1
- Microsoft Windows Server 2016 All versions including Server Core
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory