Executive brief
Windows Resilient File System (ReFS) Deduplication Service is a Windows component that optimizes storage by removing duplicate data. An authenticated local attacker can exploit a flaw in how the service resolves symbolic links to gain elevated privileges, potentially taking full control of the affected system.
Technical details
This vulnerability is a classic link-following (TOCTOU) vulnerability in the Windows ReFS Deduplication Service. An authenticated attacker with local access can manipulate symbolic links to cause the service to read or write files in unintended locations with elevated privileges. The vulnerability requires local access and existing authentication; it does not provide remote code execution. A fix is available via Windows security updates from Microsoft. An attacker exploiting this can achieve privilege escalation from a standard user to SYSTEM level.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed