Impact
An integer overflow or wraparound flaw in Windows Resilient File System (ReFS) can be triggered by an authorized local user who supplies crafted data to a ReFS volume. The overflow causes calculations to exceed memory bounds, corrupting internal structures or control flow, allowing the attacker to inject and execute arbitrary code. The impact is local code execution with the privileges of the attacker’s account, enabling the attacker to run arbitrary code on the compromised machine.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server versions 2016, 2019, 2022, and 2025 (both standard and Server Core installations). All installations that have ReFS enabled are vulnerable; disabling ReFS or migrating volumes to NTFS removes the attack surface.
Risk and Exploitability
The CVSS score of 7.8 classifies the issue as high severity, but the EPSS score of less than 1% indicates that exploitation is currently unlikely in the wild. The vulnerability does not appear in the CISA KEV catalog. The attack vector requires an authenticated local attacker with access to an ReFS volume; remote exploitation is not possible. Successful exploitation grants code execution with the local user’s privileges and could be leveraged to deploy additional malware.
OpenCVE Enrichment