Description
Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch Now
AI Analysis

Impact

The vulnerability is an out-of-bounds read in the Windows Resilient File System (ReFS) that can enable an authorized attacker to elevate privileges locally. Classified as CWE‑125, the flaw allows reading memory beyond allocated bounds, which can be abused to gain higher process privileges. The resulting local privilege escalation permits the attacker to execute privileged actions and access sensitive resources on the affected machine.

Affected Systems

Affected systems include Microsoft Windows 11 26H1, Microsoft Windows Server 2025, and the Server Core edition of Windows Server 2025. These editions run the ReFS file system on x64 architectures where the vulnerability is present.

Risk and Exploitability

The CVSS score of 7 denotes a moderate severity. The EPSS score is not available, so exploitation probability is unclear, and the vulnerability is not listed in the CISA KEV catalog. An attacker must already possess legitimate access to the target device to trigger the out‑of‑bounds read, suggesting a local attack that could be difficult to detect without additional monitoring. Given the moderate CVSS and lack of publicly documented exploits, the risk is considered significant for environments that rely on ReFS for critical data.

Generated by OpenCVE AI on September 8, 2026 at 23:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Windows cumulative update that incorporates the fix for CVE‑2026‑69617 to all affected systems.
  • If the update is unavailable, consider moving critical data off of ReFS volumes or using alternative file systems until the patch is applied.
  • Limit user permissions to ReFS or disable ReFS on nonessential volumes to reduce the attack surface.

Generated by OpenCVE AI on September 8, 2026 at 23:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
Title Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-125
CPEs cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 26h1 Windows 11 26h1 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:35:57.525Z

Reserved: 2026-08-03T21:21:00.595Z

Link: CVE-2026-69617

cve-icon Vulnrichment

Updated: 2026-09-09T09:56:44.799Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:19:33.470

Modified: 2026-09-21T14:24:17.360

Link: CVE-2026-69617

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:57:42Z

Weaknesses