Executive brief
A security vulnerability has been identified in the Windows Resilient File System (ReFS), a component used to manage data storage and ensure file integrity. An attacker who already has limited access to a system could exploit this flaw to execute malicious code with higher privileges. This could lead to a full system compromise, allowing the attacker to view sensitive data, modify files, or disrupt operations.
Technical details
This vulnerability is classified as a heap-based buffer overflow (CWE-122) within the Windows Resilient File System (ReFS) driver. The flaw is triggered when the system improperly handles specially crafted file system metadata or structures. An attacker requires local access to the target machine and must entice a user to interact with a malicious file or volume (User Interaction: Required) to trigger the overflow. Successful exploitation allows for arbitrary code execution in the context of the kernel or a highly privileged service, leading to a complete loss of confidentiality, integrity, and availability. Microsoft has released security updates to address this issue across affected Windows 10, 11, and Server 2016 versions.
Affected products
- Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 Versions 24H2, 25H2, 26H1
- Microsoft Windows Server 2016 Standard and Server Core installations
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory