Junglewise Threat Intelligence

CVE-2026-50441: Microsoft Windows ReFS untrusted pointer dereference privilege escalation

CVE-2026-50441 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Windows Resilient File System (ReFS), a component used to manage and protect large-scale data storage. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could lead to the unauthorized viewing of sensitive files, the installation of malicious software, or the disruption of business operations.

Technical details

A local privilege escalation vulnerability exists in the Microsoft Windows Resilient File System (ReFS) due to an untrusted pointer dereference (CWE-822). The flaw allows an authenticated attacker with low-level privileges to execute code with elevated system permissions by providing a specially crafted pointer that the kernel-mode driver fails to properly validate. The attack is local in nature, requiring the attacker to already have execution capabilities on the target host. Successful exploitation grants the attacker full SYSTEM-level access, compromising the confidentiality, integrity, and availability of the entire operating system. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2016 All versions

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats