Impact
A stack‑based buffer overflow (CWE‑121) exists in Windows Resilient File System (ReFS). The flaw permits an authorized local user to gain higher privileges by exploiting an overflow that occurs during normal ReFS file system operations. Executing the overflow can lead to arbitrary code execution in a higher privilege context, compromising the entire system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 24H2, 25H2, 26H1, and Windows Server 2016, 2019, 2022, 2025 (including Server Core installations) are affected. The vulnerability is tied specifically to ReFS volumes on these platforms.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity for local privilege escalation. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV, further reducing the likelihood that an active exploit is widely deployed. Based on the description, the attack vector is local and requires the attacker to have authorized file system access on a ReFS volume, although the exact prerequisites for triggering the overflow are not explicitly detailed.
OpenCVE Enrichment