Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
CVE-2024-49093

8.8HIGH

Key Information:

Summary

The Windows Resilient File System (ReFS) has been identified with a vulnerability that allows for an elevation of privilege. This issue could enable attackers to execute arbitrary code with elevated permissions, potentially compromising the integrity of affected systems. Security precautions and timely patches are essential for users running vulnerable versions of Windows Server. Microsoft has released an advisory detailing the vulnerability and recommending remedial actions to mitigate risks.

Affected Version(s)

Windows 11 Version 24H2 ARM64-based Systems 10.0.26100.0 < 10.0.26100.2605

Windows Server 2025 (Server Core installation) x64-based Systems 10.0.26100.0 < 10.0.26100.2605

Windows Server 2025 x64-based Systems 10.0.26100.0 < 10.0.26100.2605

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.