CVE-2026-50668: Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.
Other sources
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
Which systems should be prioritized for assessment?
Assess Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025 systems, including Windows 10 21H2 and 22H2. The available data does not identify specific affected build numbers.
What access does an attacker need to exploit this issue?
Exploitation requires physical access. The vector indicates no prior privileges or user interaction are required, and successful exploitation can elevate an unauthorized attacker’s privileges.
What should be done if a system is affected?
Apply the available patch. No alternative mitigations or configuration workarounds are provided in the available data.