Executive brief
A critical vulnerability has been identified in the Windows FTP Service, a component used for transferring files over a network. An unauthorized attacker can exploit this flaw remotely to take full control of the affected system without any user interaction. This could lead to the theft of sensitive data, service disruptions, or the installation of malicious software across the corporate network.
Technical details
This vulnerability is a heap-based buffer overflow (CWE-122) residing within the Windows FTP Service. The flaw can be triggered by a remote, unauthenticated attacker sending specially crafted packets over the network to a system running the affected service. Successful exploitation allows for remote code execution (RCE) in the context of the service. The vulnerability affects multiple versions of Windows 10 and Windows 11. Microsoft has released security updates to address this issue, and users are advised to apply the latest patches from the MSRC Update Guide.
Affected products
- Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
- Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
- Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
- Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
- Microsoft Windows 11 Version 23H2 10.0.22631.0 to 10.0.22631.7376
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
- Microsoft Windows 11 Version 26H1 10.0.28000.0 to 10.0.28000.2269
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory