Impact
A stack-based buffer overflow is present in the Windows Resilient File System (ReFS) driver. Based on the description, it is inferred that the overflow occurs during processing of certain file operations, where a malformed input can corrupt the stack and allow arbitrary code execution on the host. The vulnerability can compromise system integrity and confidentiality by giving an attacker the ability to run code without restrictions, potentially enabling further exploitation once the code runs.
Affected Systems
Microsoft Windows 11 builds 24H2, 25H2 and 26H1, with arm64 support for 24H2 and 25H2 and x64 support for 26H1, are affected. Windows Server 2025, including Server Core installations, is also vulnerable on all supported architectures.
Risk and Exploitability
The base CVSS score of 7.8 indicates high impact potential if a local adversary exploits the flaw. An EPSS score below 1% suggests that the likelihood of exploitation in the wild is presently very low. The vulnerability is not listed in the CISA KEV catalog, and no public exploits are known from the provided data. The attack vector is local; an attacker must be able to engage with the ReFS volume to trigger the overflow.
OpenCVE Enrichment