CVE-2026-69617
massOut-of-Bounds Read in Windows ReFS Enables Local Privilege Escalation
CVE-2026-69617 is an out-of-bounds read (CWE-125) in the Windows Resilient File System (ReFS) component, rated 7.0 (High) with local attack vector, high attack complexity, and no user interaction required. An authorized attacker with only low-level privileges on the machine can trigger the flaw through operations on a ReFS volume, causing the file system component to read beyond the intended memory boundary. Successful exploitation yields elevated privileges with high confidentiality, integrity, and availability impact, meaning the attacker effectively gains broader control of the affected system. Any Windows system using ReFS volumes — most commonly Windows Server deployments and workstation/enterprise client editions that support ReFS — is affected. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.3% probability of exploitation within 30 days, so exploitation status is considered not yet observed in the wild.
What to do: Deploy the Microsoft security update that fixes CVE-2026-69617 as soon as it is available (check the MSRC advisory for the applicable Windows builds). Inventory which systems actually host ReFS volumes (e.g., via Get-Volume/filesystem checks, especially Storage Spaces Direct clusters and backup/data servers) and prioritize patching those, since non-ReFS systems are not exposed. Until patched, restrict local sign-in and untrusted low-privilege code execution on hosts using ReFS; no public PoC or in-the-wild exploitation is currently known.
| Microsoft Windows Resilient File System (ReFS) / Windows editions supporting ReFS | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.