Impact
The vulnerability is a heap‑based buffer overflow in the Windows Resilient File System (ReFS), classified as CWE‑122. An attacker who obtains physical access to a machine can craft a malicious ReFS volume that, when mounted, causes the overflow and allows execution of arbitrary code with the privileges of the mounting process.
Affected Systems
Affected systems are Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1) and the Windows Server line (2016, 2019, 2022, 2025, including Server Core). The flaw impacts ReFS on x86, x64 and ARM64 architectures as defined by the associated CPE entries.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, while the EPSS score of less than 1% shows a low probability of exploitation. The vulnerability is not listed in CISA KEV. Exploitation requires a physical attack, such as inserting a malicious ReFS volume on the target system; no public exploit references are provided in the data.
OpenCVE Enrichment