Junglewise Threat Intelligence

CVE-2026-69617: Microsoft Windows Resilient File System out-of-bounds read

CVE-2026-69617 · Severity: high · CVSS 7 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Resilient File System (ReFS) is a file system component that manages how data is stored and retrieved on modern Windows systems. A vulnerability allows an authorized local user to read memory beyond intended boundaries, potentially allowing them to elevate their privileges on the affected computer and gain administrative access.

Technical details

An out-of-bounds read vulnerability exists in the Windows Resilient File System (ReFS) driver. The vulnerability allows an authenticated local attacker to read memory regions outside the intended bounds, which can be leveraged to disclose sensitive information or bypass security mechanisms. The attack requires local access and prior authentication on the target system. Successful exploitation can lead to privilege escalation from a standard user to administrator/system level.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats