ZeroHour

CVE-2026-83999

large

Local Privilege Escalation via Link Following in Windows ReFS Deduplication Service

CVSS 3.1
7.0 high
EPSS
<1%p11
Published
()
Modified
AI analysis

CVE-2026-83999 is a local privilege elevation flaw caused by improper link resolution before file access (CWE-59, 'link following') in the Windows Resilient File System (ReFS) Deduplication Service. A local, authorized attacker with low privileges can trigger it by manipulating how the dedup service resolves file links while processing ReFS volumes; the attack is high-complexity but requires no user interaction or remote access. Successful exploitation grants the attacker elevated privileges on the local machine, with high impact to confidentiality, integrity, and availability. Affected systems are Windows 11 24H2, 25H2, and 26H1 and Windows Server 2025 where ReFS volumes with deduplication are used. There is no known public proof-of-concept, it is not listed in CISA KEV, EPSS is low (0.2%, 12th percentile), and no in-the-wild exploitation has been reported as of the September 2026 Patch Tuesday cycle.

What to do: Apply Microsoft's September 2026 cumulative security updates for Windows 11 24H2/25H2/26H1 and Windows Server 2025. Prioritize patching hosts where ReFS deduplication is actually enabled (e.g., Windows Server 2025 storage servers and ReFS-based data volumes), and check which systems use ReFS dedup to focus remediation. As an interim mitigation, limit low-privileged local logon access on systems running the ReFS Deduplication Service.

Affected
microsoft Windows 11 24H2
microsoft Windows 11 25H2
microsoft Windows 11 26H1
microsoft Windows Server 2025
Estimated exposure
largelikely on the order of 100,000 to 1,000,000 systems — Windows 11 24H2-or-later and Windows Server 2025 have a combined installed base of hundreds of millions of devices, but the vulnerable service is exercised only on systems using ReFS volumes with deduplication enabled, an opt-in storage…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2025
Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities and 2 Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including two zero-days already exploited in the wild.

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, and Azure components, including two zero-days already exploited in the wild. CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, is flagged as an exploited zero-day. The release includes numerous remote code execution and information disclosure fixes for Microsoft Excel and Word, plus patches for the Windows kernel, ALPC, Print Spooler, ReFS, Entra ID, and Azure CLI.

GBHackers · 7d agoAdvisory in the wildCVE-2026-85880CVE-2026-85877CVE-2026-85875+27 CVEs