CVE-2026-83952
massHeap Buffer Overflow in Microsoft Windows ReFS Enables Local Privilege Escalation
CVE-2026-83952 is a heap-based buffer overflow (CWE-122) in Microsoft's Windows Resilient File System (ReFS), the file system driver used for resilient volumes on Windows servers and high-end workstations. Per the description, an authorized local attacker with low privileges can trigger the overflow through operations on an affected system's ReFS volumes, with no user interaction required. Successful exploitation allows the attacker to elevate privileges locally, with high impact on confidentiality, integrity, and availability — i.e., gaining elevated rights on the host. Any Windows deployment that includes and mounts ReFS volumes is plausibly affected, though the provided data does not enumerate specific affected Windows builds, which defenders should confirm in Microsoft's advisory. There is currently no evidence of exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns only a 0.2% probability of exploitation within 30 days (16th percentile).
What to do: Install the Windows security update addressing CVE-2026-83952 via Windows Update or the Microsoft Update Catalog on all affected systems, prioritizing file servers, Storage Spaces/Storage Spaces Direct hosts, and workstations that mount ReFS volumes; consult Microsoft's advisory for the exact affected builds, which were not enumerated in the provided data. Until patched, restrict local sign-in and standard-user rights on sensitive hosts using ReFS, and verify ReFS usage on critical servers (e.g., with Get-Volume or fsutil fsinfo volumeinfo).
| Microsoft Windows Resilient File System (ReFS) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.