Description
Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack-based buffer overflow is present in the Windows Resilient File System (ReFS) driver. Based on the description, it is inferred that the overflow occurs during processing of certain file operations, where a malformed input can corrupt the stack and allow arbitrary code execution on the host. The vulnerability can compromise system integrity and confidentiality by giving an attacker the ability to run code without restrictions, potentially enabling further exploitation once the code runs.

Affected Systems

Microsoft Windows 11 builds 24H2, 25H2 and 26H1, with arm64 support for 24H2 and 25H2 and x64 support for 26H1, are affected. Windows Server 2025, including Server Core installations, is also vulnerable on all supported architectures.

Risk and Exploitability

The base CVSS score of 7.8 indicates high impact potential if a local adversary exploits the flaw. An EPSS score below 1% suggests that the likelihood of exploitation in the wild is presently very low. The vulnerability is not listed in the CISA KEV catalog, and no public exploits are known from the provided data. The attack vector is local; an attacker must be able to engage with the ReFS volume to trigger the overflow.

Generated by OpenCVE AI on July 31, 2026 at 07:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest cumulative update from Microsoft that addresses CVE-2026-50501.
  • Enable automatic delivery of security updates via Windows Update or Microsoft Endpoint Manager.
  • Restrict local user access to ReFS volumes and consider disabling ReFS if it is not required for business operations.

Generated by OpenCVE AI on July 31, 2026 at 07:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
Title Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-121
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:56:17.903Z

Reserved: 2026-06-04T18:59:53.337Z

Link: CVE-2026-50501

cve-icon Vulnrichment

Updated: 2026-07-14T18:46:57.120Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:30:04Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow