Impact
A numeric truncation error exists in the Windows Resilient File System (ReFS) kernel component. When an authorized local user invokes a vulnerable operation, the truncation allows arbitrary code execution within the context of elevated privileges. Because the flaw falls under CWE‑197, the issue arises from improper handling of numeric values leading to memory corruption. The result is a local attack that can compromise confidentiality, integrity, and availability of the affected system by allowing the victim to execute malicious code with higher permissions.
Affected Systems
Microsoft Windows 10 releases from 1607 through 22H2, Windows 11 releases 24H2, 25H2, and 26H1, and Windows Server releases 2016, 2019, 2022, and 2025, including Server Core installations. All these variants are affected by the ReFS vulnerability.
Risk and Exploitability
The flaw has a CVSS score of 7.8, indicating high severity; an EPSS score of less than 1% suggests a low probability of exploitation in the wild, and it is not listed in the CISA KEV catalog. Because only an authorized local user can trigger the error, the likely attack vector is a local privilege escalation scenario, meaning that legitimate users or processes with local access could exploit the flaw to run arbitrary code with elevated rights. Environments relying heavily on ReFS volumes face greater risk if privileged users can access those file systems.
OpenCVE Enrichment