Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-49792

CVE-2026-49792: Windows 10 1607 ReFS RCE Vulnerability

CVE-2026-49792 is a remote code execution vulnerability in Windows 10 1607 Resilient File System caused by numeric truncation error. Authorized attackers can exploit this to execute code locally on affected systems.

Published:

CVE-2026-49792 Overview

CVE-2026-49792 is a numeric truncation error [CWE-197] in the Windows Resilient File System (ReFS) driver. An authorized local attacker can exploit the flaw to execute code with elevated privileges on the affected host. Microsoft rates the issue High severity with a CVSS 3.1 base score of 7.8. The vulnerability affects a broad range of client and server SKUs, including Windows 10, Windows 11, and Windows Server 2016 through Windows Server 2025. No public exploit code and no evidence of in-the-wild exploitation have been reported as of the publication date.

Critical Impact

A local, authenticated attacker who triggers the truncation flaw in the ReFS driver can execute arbitrary code and compromise the confidentiality, integrity, and availability of the affected Windows system.

Affected Products

  • Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2) on x86, x64, and ARM64
  • Microsoft Windows 11 (versions 24H2, 25H2, 26H1) on x64 and ARM64
  • Microsoft Windows Server 2016, 2019, 2022, and 2025

Discovery Timeline

  • 2026-07-14 - CVE-2026-49792 published to the National Vulnerability Database
  • 2026-07-20 - Last updated in the NVD database

Technical Details for CVE-2026-49792

Vulnerability Analysis

The flaw resides in the Windows Resilient File System (ReFS) kernel-mode driver. ReFS is Microsoft's next-generation file system, designed for large data volumes, storage pools, and virtualized workloads. The driver mishandles a numeric conversion when processing an attacker-controlled value, truncating a wider integer into a smaller data type. This truncated value is subsequently used in a downstream memory operation, allowing the attacker to influence sizes or offsets outside the intended range. Successful exploitation yields local code execution in the security context of the vulnerable component, which for a file system driver is typically kernel or SYSTEM level.

Root Cause

The underlying weakness is a numeric truncation error [CWE-197]. When the ReFS driver converts a larger integer type (such as a 64-bit length or offset) into a smaller integer type (such as a 32-bit or 16-bit value) without proper range validation, the high-order bits are silently discarded. The resulting value no longer represents the original quantity and can wrap or shrink unexpectedly. Subsequent allocation, bounds-check, or pointer-arithmetic logic then operates on an inconsistent size, opening a path to memory corruption.

Attack Vector

Exploitation requires local access and low-privileged authenticated credentials on the target system. No user interaction is required. An attacker crafts a malicious ReFS structure — for example, a specially formed volume, metadata record, or file system request — and induces the driver to parse it. When the truncated value flows into a size or offset used by the driver, memory corruption occurs in the kernel. The attacker leverages this corruption to hijack control flow or overwrite privileged data, achieving code execution with elevated privileges. See the Microsoft Security Update CVE-2026-49792 advisory for the vendor's technical description.

Detection Methods for CVE-2026-49792

Indicators of Compromise

  • Unexpected mounting or attachment of ReFS-formatted virtual hard disks (.vhd, .vhdx) by non-administrative users
  • System crashes or bug checks (Blue Screen) referencing the refs.sys or refsv1.sys drivers
  • New privileged processes spawned by user-context processes shortly after ReFS I/O activity

Detection Strategies

  • Hunt for low-privileged user sessions invoking format, mountvol, or diskpart operations against ReFS volumes
  • Correlate Windows kernel bug-check events (Event ID 1001, source BugCheck) with the loading of ReFS-related drivers
  • Alert on token elevation or process integrity changes following file system driver activity from standard-user accounts

Monitoring Recommendations

  • Enable Sysmon Event IDs 1 (process create), 6 (driver loaded), and 11 (file create) with rules focused on ReFS operations
  • Forward Windows kernel and storage-related event logs to a centralized SIEM for baseline deviation analysis
  • Monitor for creation of arbitrary VHD/VHDX images by non-administrative users, particularly those subsequently mounted

How to Mitigate CVE-2026-49792

Immediate Actions Required

  • Apply the Microsoft security update referenced in the MSRC advisory to all affected Windows client and server systems
  • Prioritize patching on multi-user systems, terminal servers, and hosts where low-privileged users can attach arbitrary storage
  • Audit local account membership and remove unnecessary interactive logon rights on high-value hosts

Patch Information

Microsoft has issued official security updates through the Microsoft Update Guide. Administrators should deploy the vendor-supplied patches for each affected Windows 10, Windows 11, and Windows Server build listed in the advisory. Consult the Microsoft Security Update CVE-2026-49792 page for the exact KB article numbers applicable to each supported version and architecture.

Workarounds

  • Restrict the ability of standard users to mount arbitrary VHD/VHDX images or removable media containing ReFS volumes
  • Where ReFS is not required, prefer NTFS for volumes accessed by low-privileged workloads to reduce attack surface
  • Enforce application allowlisting and least-privilege policies to limit which accounts can trigger ReFS driver code paths
bash
# Configuration example: enumerate ReFS volumes and identify hosts requiring priority patching
Get-Volume | Where-Object { $_.FileSystemType -eq 'ReFS' } | Select-Object DriveLetter, FileSystemLabel, SizeRemaining, Size

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.