Microsoft published security guidance for multiple vulnerabilities in Windows Resilient File System (ReFS), including elevation-of-privilege issues tracked as CVE-2025-55687 and CVE-2026-23673. The company listed both flaws in its Security Update Guide, with CVE-2026-23673 appearing in both advisory and vulnerability entries, indicating coordinated documentation around the same ReFS privilege-escalation issue.
The disclosures also connect to an earlier remote code execution flaw in the same Windows component, CVE-2022-21892, showing that ReFS has been the subject of repeated security fixes across multiple years. Together, the references indicate ongoing Microsoft remediation for security weaknesses in the Windows file system layer that could allow attackers to gain higher privileges or, in the earlier case, execute code through ReFS-related attack paths.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft published Security Update Guide entries for CVE-2026-23673, describing it as a Windows Resilient File System (ReFS) elevation of privilege vulnerability. The advisory and vulnerability references appear to document the same disclosure event.
Microsoft added CVE-2025-55687 to its Security Update Guide as a Windows Resilient File System (ReFS) elevation of privilege vulnerability.
Microsoft published security guidance for CVE-2022-21892, a Windows Resilient File System (ReFS) remote code execution vulnerability.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceportal.msrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.