CVE-2026-83999: Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.
Details
Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83999
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-83999 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Windows Resilient File
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-83999: Improper link resolution before file access ('link following') in Windows Resilient File Syste…nvd · 2026-09-08
- highCVE-2026-83952: Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attack…nvd · 2026-09-08
- highCVE-2026-69617: Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to el…nvd · 2026-09-08
- highCVE-2026-69617: Windows Resilient File System (ReFS) Elevation of Privilege Vulnerabilitymsrc · 2026-09-08
- highCVE-2026-83952: Windows Resilient File System (ReFS) Elevation of Privilege Vulnerabilitymsrc · 2026-09-08
- highCVE-2026-58530: Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized atta…nvd · 2026-07-14
More from Microsoft Security Response Center
- unknownCVE-2026-85062: Colord: Slow rejection of oversized malformed color strings2026-09-08
- mediumCVE-2026-18924: HTTP/2 server push UAF2026-09-08
- highCVE-2026-69630: Windows Win32k Elevation of Privilege Vulnerability2026-09-08
- mediumCVE-2026-80834: crypto: sun8i-ce - Remove crypto_rng interface2026-09-08
- unknownCVE-2026-83616: xmldom: Processing Instruction Target Injection Bypasses requireWellFormed2026-09-08