ZeroHour

CVE-2026-69617

mass

Out-of-Bounds Read in Windows ReFS Enables Local Privilege Escalation

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69617 is an out-of-bounds read (CWE-125) in the Windows Resilient File System (ReFS) component, rated 7.0 (High) with local attack vector, high attack complexity, and no user interaction required. An authorized attacker with only low-level privileges on the machine can trigger the flaw through operations on a ReFS volume, causing the file system component to read beyond the intended memory boundary. Successful exploitation yields elevated privileges with high confidentiality, integrity, and availability impact, meaning the attacker effectively gains broader control of the affected system. Any Windows system using ReFS volumes — most commonly Windows Server deployments and workstation/enterprise client editions that support ReFS — is affected. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.3% probability of exploitation within 30 days, so exploitation status is considered not yet observed in the wild.

What to do: Deploy the Microsoft security update that fixes CVE-2026-69617 as soon as it is available (check the MSRC advisory for the applicable Windows builds). Inventory which systems actually host ReFS volumes (e.g., via Get-Volume/filesystem checks, especially Storage Spaces Direct clusters and backup/data servers) and prioritize patching those, since non-ReFS systems are not exposed. Until patched, restrict local sign-in and untrusted low-privilege code execution on hosts using ReFS; no public PoC or in-the-wild exploitation is currently known.

Affected
Microsoft Windows Resilient File System (ReFS) / Windows editions supporting ReFS
Estimated exposure
masstens of millions of Windows installations include ReFS support; likely well over 1M servers and workstations with ReFS volumes in use (est.) — ReFS ships with Windows Server SKUs and Windows Pro for Workstations/Enterprise, so given the very large Windows/Windows Server installed base, the number of systems with ReFS available — and plausibly ReFS volumes in active use (e.g.,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.