Impact
A heap-based buffer overflow in the Windows Resilient File System (ReFS) allows an attacker who can influence ReFS data structures to execute arbitrary code on the affected system. The resulting local code execution grants the attacker whatever privileges the initiating user possesses, potentially enabling malicious modification of ReFS volumes or further privilege escalation within that scope. The vulnerability is described as a classic buffer overflow identified by CWE-122.
Affected Systems
Affected products include Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 24H2, 25H2 and 26H1; and Microsoft Windows Server 2016, 2019, 2022 and 2025, including Server Core installations. The flaw impacts x86, x64, and ARM64 architectures wherever ReFS is installed.
Risk and Exploitability
The CVSS score of 7.8 categorizes this flaw as high severity, yet the EPSS score of <1% indicates a low current likelihood of exploitation, and it is not listed in the CISA KEV catalog. Exploitation requires local access to a ReFS volume and the ability to craft malformed data that triggers the overflow. Because the attack vector is local, any user with write permissions on a vulnerable ReFS volume could potentially execute code with that user's rights, which could be leveraged for privilege escalation or other malicious activity.
OpenCVE Enrichment