Impact
Heap-based buffer overflow in the Windows Resilient File System (ReFS) allows an authorized local attacker to gain higher privileges on the affected system. This flaw does not bypass authentication, but an attacker who can write to a ReFS volume can trigger the overflow and achieve local system or administrator rights, potentially allowing full compromise of the machine’s confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects Microsoft Windows 11 in the 24H2, 25H2 and 26H1 release streams, as well as Microsoft Windows Server 2025, including its Server Core installation.
Risk and Exploitability
The flaw carries a CVSS score of 7.8. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, indicating it has not yet been widely exploited. Based on the description, the attack vector is inferred to be local; an attacker must have authorized access to the system and write permissions to a ReFS volume to trigger the buffer overflow and elevate privileges.
OpenCVE Enrichment