ZeroHour

CVE-2026-83952

mass

Heap Buffer Overflow in Microsoft Windows ReFS Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-83952 is a heap-based buffer overflow (CWE-122) in Microsoft's Windows Resilient File System (ReFS), the file system driver used for resilient volumes on Windows servers and high-end workstations. Per the description, an authorized local attacker with low privileges can trigger the overflow through operations on an affected system's ReFS volumes, with no user interaction required. Successful exploitation allows the attacker to elevate privileges locally, with high impact on confidentiality, integrity, and availability — i.e., gaining elevated rights on the host. Any Windows deployment that includes and mounts ReFS volumes is plausibly affected, though the provided data does not enumerate specific affected Windows builds, which defenders should confirm in Microsoft's advisory. There is currently no evidence of exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns only a 0.2% probability of exploitation within 30 days (16th percentile).

What to do: Install the Windows security update addressing CVE-2026-83952 via Windows Update or the Microsoft Update Catalog on all affected systems, prioritizing file servers, Storage Spaces/Storage Spaces Direct hosts, and workstations that mount ReFS volumes; consult Microsoft's advisory for the exact affected builds, which were not enumerated in the provided data. Until patched, restrict local sign-in and standard-user rights on sensitive hosts using ReFS, and verify ReFS usage on critical servers (e.g., with Get-Volume or fsutil fsinfo volumeinfo).

Affected
Microsoft Windows Resilient File System (ReFS)
Estimated exposure
mass≈100M+ Windows devices include the ReFS component, with millions of servers and workstations actively running ReFS volumes — ReFS is a built-in file system in Windows Server and Windows client editions that support it, so the enterprise Windows installed base (hundreds of millions of devices) includes the vulnerable component, with practical exploitability…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.