Impact
A numeric truncation error in Windows Resilient File System (ReFS) allows an attacker who has authorized local access to execute arbitrary code on the system. The flaw arises when ReFS processes numeric values that are incorrectly truncated, allowing the attacker to manipulate internal structures and trigger code execution. This flaw is a numeric truncation error (CWE-197).
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Microsoft Windows 11 versions 24H2, 25H2 and 26H1; Microsoft Windows Server 2016, 2019, 2022 and 2025; all architectures and Server Core installations are affected.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score is below 1%, suggesting a very low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, requiring an authorized user to access the system and manipulate an ReFS volume to achieve code execution. No remote attack vector is documented.
OpenCVE Enrichment