CVE-2025-27738

Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network.

  • Published Apr 8, 2025
  • CVSS 6.5 medium
  • 3.4% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2025-27738 at the National Vulnerability Database