
CVE-2026-69379: TOCTOU in ReFsDedupSvc Enables Arbitrary File Overwrite as SYSTEM
A process-wide SE_RESTORE_PRIVILEGE and a destination lock released four operations too early. Neither is a bug on its own; chained, they let a standard user overwrite TrustedInstaller-owned files in System32.
