Impact
The vulnerability is an out-of-bounds read in the Windows Resilient File System (ReFS) that can enable an authorized attacker to elevate privileges locally. Classified as CWE‑125, the flaw allows reading memory beyond allocated bounds, which can be abused to gain higher process privileges. The resulting local privilege escalation permits the attacker to execute privileged actions and access sensitive resources on the affected machine.
Affected Systems
Affected systems include Microsoft Windows 11 26H1, Microsoft Windows Server 2025, and the Server Core edition of Windows Server 2025. These editions run the ReFS file system on x64 architectures where the vulnerability is present.
Risk and Exploitability
The CVSS score of 7 denotes a moderate severity. The EPSS score is not available, so exploitation probability is unclear, and the vulnerability is not listed in the CISA KEV catalog. An attacker must already possess legitimate access to the target device to trigger the out‑of‑bounds read, suggesting a local attack that could be difficult to detect without additional monitoring. Given the moderate CVSS and lack of publicly documented exploits, the risk is considered significant for environments that rely on ReFS for critical data.
OpenCVE Enrichment