Junglewise Threat Intelligence

CVE-2026-83952: Microsoft Windows ReFS heap-based buffer overflow

CVE-2026-83952 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Resilient File System (ReFS) is a file system component used by Windows Server and some Windows client operating systems to manage data storage. A heap-based buffer overflow vulnerability allows an authorized attacker on a compromised system to execute arbitrary code with elevated privileges, potentially leading to full system compromise or the ability to access sensitive data without restriction.

Technical details

A heap-based buffer overflow exists in the Windows Resilient File System (ReFS) driver code. The vulnerability is triggered during file system operations and can be exploited by an authenticated attacker with local access to the system. Successful exploitation allows the attacker to overwrite heap memory structures and achieve local privilege escalation, gaining SYSTEM-level access. The attack vector is local and requires prior system access, limiting the immediate attack surface. A patch is available from Microsoft via the Security Update Guide.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory

References

Related threats