CVE-2025-62456
published 2025-12-09CVE-2025-62456: Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network.
PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.04%
60.2th percentile
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_11_23h2 | < 10.0.22631.6345 | 10.0.22631.6345 |
| microsoft | windows_11_24h2 | < 10.0.26100.7392 | 10.0.26100.7392 |
| microsoft | windows_11_25h2 | < 10.0.26200.7392 | 10.0.26200.7392 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.6345 | 10.0.22631.6345 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.6345 | 10.0.22631.6345 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.7462 | 10.0.26100.7462 |
| microsoft | windows_11_version_25h2 | >= 10.0.26200.0 < 10.0.26200.7462 | 10.0.26200.7462 |
| microsoft | windows_server_2022 | < 10.0.20348.4467 | 10.0.20348.4467 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.4529 | 10.0.20348.4529 |
| microsoft | windows_server_2022_23h2 | < 10.0.25398.2025 | 10.0.25398.2025 |
| microsoft | windows_server_2025 | < 10.0.26100.7392 | 10.0.26100.7392 |
| microsoft | windows_server_2025 | >= 10.0.26100.0 < 10.0.26100.7462 | 10.0.26100.7462 |
| msrc | windows_11_version_23h2_for_arm64-based_systems | — | — |
| msrc | windows_11_version_23h2_for_x64-based_systems | — | — |
| msrc | windows_11_version_24h2_for_arm64-based_systems | — | — |
| msrc | windows_11_version_24h2_for_x64-based_systems | — | — |
| msrc | windows_11_version_25h2_for_arm64-based_systems | — | — |
| msrc | windows_11_version_25h2_for_x64-based_systems | — | — |
| msrc | windows_server_2022 | — | — |
| msrc | windows_server_2022_23h2_edition | — | — |
| msrc | windows_server_2025 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →An authenticated attacker exploits this via a specially crafted operation against a shared folder on a ReFS volume — monitor for anomalous SMB/network file operations targeting ReFS-formatted shares, particularly from low-privileged authenticated users. ↗
- →No admin or elevated privileges are required to trigger this vulnerability — any authenticated network user is a potential threat actor; baseline and alert on unusual ReFS share access patterns from standard user accounts. ↗
- ·No public exploit exists as of the publication date; exploitation is assessed as unlikely by Microsoft, but EPSS score of 28.2 percentile warrants monitoring. ↗
- ·The vulnerability is network-exploitable (attack vector: network) against systems hosting ReFS volumes with shared folders exposed over the network — restrict unnecessary ReFS share exposure. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
vendor_msrc·2025-12-09·CVSS 8.8
CVE-2025-62456 [HIGH] CWE-122 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Description: Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network.
FAQ: How could an attacker exploit this vulnerability?
An authenticated attacker with access to a shared folder on a system using a Resilient File System (ReFS) volume could exploit this vulnerability by running a specially crafted operation against the folder.
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.
Windows Resilient File System (ReFS): Windows Resilient File System (ReFS)
Microsoft: M
GHSA
GHSA-qrrp-v5pw-7w99: Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network
ghsa_unreviewed·2025-12-09
CVE-2025-62456 [HIGH] CWE-122 GHSA-qrrp-v5pw-7w99: Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network.
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday for December 2025 — Snort rules and prominent vulnerabilities
blogs_talos·2025-12-09·CVSS 8.8
[HIGH] Microsoft Patch Tuesday for December 2025 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for December 2025 — Snort rules and prominent vulnerabilities
The Patch Tuesday for December of 2025 includes 57 vulnerabilities, including two that Microsoft marked as “critical.” The remaining vulnerabilities listed are classified as “important.” Microsoft assessed that exploitation of the two “critical” vulnerabilities is “less likely.”
CVE‑2025‑62562 is a Microsoft Outlook remote code execution vulnerability. Although it involves a use after free in Microsoft Office Outlook to allow an unauthorized attacker to execute code locally, an attacker would still need to send a malicious email and persuade the user to reply to it for the exploit to work.
CVE-2025-62553 , CVE-2025-62554 , CVE-2025-62556 and CVE-2025-62557 are Microsoft Office Remote Code Execution
Talos
Microsoft Patch Tuesday for December 2025 — Snort rules and prominent vulnerabilities
blogs_talos·2025-12-09·CVSS 8.8
[HIGH] Microsoft Patch Tuesday for December 2025 — Snort rules and prominent vulnerabilities
The Patch Tuesday for December of 2025 includes 57 vulnerabilities, including two that Microsoft marked as “critical.” The remaining vulnerabilities listed are classified as “important.” Microsoft assessed that exploitation of the two “critical” vulnerabilities is “less likely.”
CVE‑2025‑62562 is a Microsoft Outlook remote code execution vulnerability. Although it involves a use after free in Microsoft Office Outlook to allow an unauthorized attacker to execute code locally, an attacker would still need to send a malicious email and persuade the user to reply to it for the exploit to work.
CVE-2025-62553, CVE-2025-62554, CVE-2025-62556 and CVE-2025-62557 are Microsoft Office Remote Code Execution Vulnerability. An attacker can access resources using incompatible type ('type confusion') o
Bleepingcomputer
Microsoft December 2025 Patch Tuesday fixes 3 zero-days, 57 flaws
blogs_bleepingcomputer·2025-12-09·CVSS 7.8
[HIGH] Microsoft December 2025 Patch Tuesday fixes 3 zero-days, 57 flaws
## Microsoft December 2025 Patch Tuesday fixes 3 zero-days, 57 flaws
## Lawrence Abrams
28 Elevation of Privilege Vulnerabilities
19 Remote Code Execution Vulnerabilities
4 Information Disclosure Vulnerabilities
3 Denial of Service Vulnerabilities
2 Spoofing Vulnerabilities
When BleepingComputer reports on Patch Tuesday security updates, we only count those released by Microsoft today. Therefore, the number of flaws does not include Microsoft Edge (15 flaws) and Mariner vulnerabilities fixed earlier this month.
To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5072033 & KB5071417 cumulative updates .
If you're facing delays, blind spots, or prioritization issues with Patch Tuesday updates, our recent webinar with
Wiz
CVE-2025-62456 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-62456 [HIGH] CVE-2025-62456 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-62456 :
vulnerability analysis and mitigation
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network.
Source : NVD
## 8.8
Score
Published December 9, 2025
Severity HIGH
CNA Score 8.8
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 28.2
Exploitation Probability (EPSS) 0.1
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
Free Vulnerability Assessment
## Benchmark your Cloud Security Posture
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify
2025-12-09
Published