Impact
A heap-based buffer overflow exists in the Windows Resilient File System (Re crafted data that overflows an internal memory buffer and causes the driver to execute arbitrary code. This delivers the attacker the privileges of the compromised account, potentially threatening the confidentiality, integrity, and availability of the affected system.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, and 22H2), Windows 11 (versions 24H2, 25H2, and 26H1), and Windows Server 2016, 2019, 2022, and 2025—including Server Core editions that employ ReFS volumes. Any system with ReFS disks where a user holds write permissions is susceptible.
Risk and Exploitability
The CVSS score of 7.8 classifies this as high severity for local attackers. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local user with write access to a ReFS volume; no. No public exploit has been disclosed, which reduces the immediacy of the threat but does not eliminate the need to patch or mitigate.
OpenCVE Enrichment