
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62456 is a heap-based buffer overflow vulnerability in Windows Resilient File System (ReFS) that allows an authenticated, low-privileged attacker to execute arbitrary code remotely over a network. It was disclosed and patched on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday. Affected products include Windows 11 (versions 23H2, 24H2, 25H2), Windows Server 2022, Windows Server 2022 23H2 Edition, and Windows Server 2025. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Microsoft MSRC).
The root cause is a heap-based buffer overflow (CWE-122) in the Windows Resilient File System (ReFS) driver, mapped to CAPEC-92 (Forced Integer Overflow). An attacker with low privileges can trigger the overflow by performing specially crafted operations against shared folders hosted on ReFS volumes, requiring no user interaction. The attack vector is network-based with low attack complexity, meaning exploitation does not require special conditions beyond authenticated network access. No public proof-of-concept or detailed technical write-up has been published as of the disclosure date (Microsoft MSRC, Feedly).
Successful exploitation grants an attacker the ability to execute arbitrary code in the context of the affected system, resulting in complete compromise of confidentiality, integrity, and availability. An attacker could gain unauthorized access to sensitive data, corrupt or destroy file system data, and potentially take full control of the affected Windows host. In enterprise environments with shared ReFS volumes, this vulnerability poses a significant lateral movement risk, as any authenticated network user could trigger the flaw without elevated privileges (Microsoft MSRC).
Microsoft released security updates on December 9, 2025, addressing this vulnerability across all affected platforms. Administrators should apply the following patched builds: Windows 11 23H2 → 10.0.22631.6345, Windows 11 24H2 / Windows Server 2025 → 10.0.26100.7392, Windows 11 25H2 → 10.0.26200.7392, Windows Server 2022 → 10.0.20348.4467, Windows Server 2022 23H2 → 10.0.25398.2025. As interim mitigations, organizations should restrict network access to ReFS-hosted shares, implement network segmentation to limit exposure, and monitor system logs for anomalous activity targeting file server resources (Microsoft MSRC).
The vulnerability was covered as part of broader December 2025 Patch Tuesday reporting by multiple security outlets. Cisco Talos highlighted it among notable vulnerabilities in their monthly patch review, and Sophos included it in their December Patch Tuesday analysis (Talos Blog, Sophos News). Zero Day Initiative (ZDI) also reviewed the December 2025 update batch, which included this flaw (ZDI Blog). Community reaction was moderate, with the vulnerability noted as significant due to its network-exploitable, low-privilege attack vector, though the absence of a public PoC tempered urgency.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."