Description
Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an untrusted pointer dereference in the Windows Resilient File System (ReFS). When processed, the kernel trusts data from a ReFS volume and dereferences a pointer that can be manipulated by an attacker who has local access. Exploitation allows the attacker to gain higher privileges on the system, effectively elevating the user’s credentials from a standard account to an administrative one. This weakness is classified as CWE‑822 and presents a clear escalation of authority without needing remote access.

Affected Systems

The vulnerability impacts multiple Microsoft Windows builds. The affected consumer operating systems are Windows 10 versions 1607, 1809, 21H2, and 22H2, as well as Windows 11 versions 24H2, 25H2, and 26H1. Server deployments that are affected include Windows Server 2016 (full and Server Core), Windows Server 2019 (full and Server Core), Windows Server 2022, and Windows Server 2025 (full and Server Core). All listed systems use the ReFS file system, which is the component that contains the vulnerable code.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity local privilege escalation burden. EPSS is reported as < 1 %, suggesting that, while the vulnerability exists, it is unlikely to be widely exploited at present. The vulnerability is not listed in CISA’s KEV catalog, further indicating limited exploitation activity. The attack vector is inferred to be local: an attacker who can write or manipulate a ReFS volume file that the system will later read. Such an attacker could trigger the dereference during normal system operations, altering object ownership or permission bits. The limited attack surface and lack of remote exploitation pathways reduce the immediate risk, but the high CVSS still warrants prompt response.

Generated by OpenCVE AI on July 31, 2026 at 07:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Windows update that includes the ReFS patch for CVE-2026-50441, using Windows Update or the Microsoft Update Catalog.
  • Restrict access to ReFS volumes by moving critical data to NTFS or disabling ReFS on systems where it is unnecessary, thereby eliminating the attack surface.
  • Enable detailed audit logging for filesystem operations and review logs for anomalous ReFS activity that could indicate exploitation attempts.

Generated by OpenCVE AI on July 31, 2026 at 07:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
Title Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-822
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:55:45.436Z

Reserved: 2026-06-04T18:57:47.376Z

Link: CVE-2026-50441

cve-icon Vulnrichment

Updated: 2026-07-15T10:53:02.747Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T08:00:04Z

Weaknesses
  • CWE-822

    Untrusted Pointer Dereference