Junglewise Threat Intelligence

CVE-2026-45636: Microsoft Windows NTFS heap overflow

CVE-2026-45636 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Microsoft Windows NTFS. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Windows NTFS file system, which is the primary system used by Windows to store and retrieve files on hard drives. An attacker who already has limited access to a computer could exploit this flaw to gain full control over the system, potentially leading to data theft or the installation of malicious software. This issue requires a user to perform a specific action, such as opening a malicious file, to trigger the exploit.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in the Microsoft Windows NTFS driver due to improper input validation (CWE-20). The vulnerability is triggered when the system processes specially crafted file system metadata. An attacker with local access can exploit this by convincing a user to interact with a malicious file or partition, leading to arbitrary code execution with elevated privileges. The attack vector is local, requiring user interaction (UI:R), and provides high impact to confidentiality, integrity, and availability. Microsoft has released information regarding this vulnerability via their Security Update Guide.

Affected products

  • Microsoft Windows NTFS

Timeline

  • 2026-06-09: disclosed: Vulnerability published by Microsoft and NVD.
  • 2026-06-09: advisory: Microsoft Security Update Guide entry created.

References

Related threats