Impact
A heap-based buffer overflow occurs within the Windows Resilient File System (ReFS) processing code, allowing an attacker who already has local access to the system to elevate privileges. The vulnerability is described as CWE-122, which represents heap-based overflow weaknesses that can corrupt memory and alter program flow, potentially granting the attacker higher privileges and enabling further exploitation.
Affected Systems
Affected Windows operating systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; and the Windows Server family from 2016 through 2025, including both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity rating, while the EPSS score of less than 1% indicates that the vulnerability is expected to be rarely exploited in the wild and is not listed in the CISA KEV catalog. Attackers would need local presence with permission to write to a ReFS volume, implying that the threat vector is local. Because the vulnerability is not widely exploited and currently has no known public exploit, the risk is primarily mitigated by applying the vendor’s patch. However, any breach that provides local authenticated or administrative access could leverage this flaw to gain elevated rights.
OpenCVE Enrichment