Executive brief
A security vulnerability exists in the Windows Resilient File System (ReFS), a component used to manage and protect large-scale data storage. An attacker who already has basic access to a computer could exploit this flaw to run malicious code with elevated privileges. This could lead to a full system takeover, unauthorized access to sensitive files, or disruption of business operations.
Technical details
This vulnerability is classified as an integer overflow or wraparound (CWE-190) leading to a heap-based buffer overflow (CWE-122) within the Windows Resilient File System (ReFS) driver. The flaw is triggered during the processing of specific file system operations. An attacker with low-privileged local access can exploit this to execute code in the context of the kernel or a highly privileged service. The attack vector is local, requiring no user interaction, and results in a complete compromise of confidentiality, integrity, and availability. Microsoft has released security updates to address this issue across affected Windows 10, 11, and Server versions.
Affected products
- Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 Versions 24H2, 25H2, 26H1
- Microsoft Windows Server 2016 All versions
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory