Junglewise Threat Intelligence

CVE-2026-50341: Microsoft Windows NTFS buffer over-read information disclosure

CVE-2026-50341 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows NTFS file system, which is the primary system used by Windows to store and retrieve files on hard drives. An authorized user with low-level access to a computer could exploit this flaw to view sensitive information that should normally be protected. This could lead to the unauthorized disclosure of system or user data, though it requires the attacker to already have a foothold on the device.

Technical details

A buffer over-read vulnerability (CWE-126) exists within the Windows NTFS driver. The flaw is triggered when the system fails to properly validate the length of data being read from a buffer, allowing an attacker to read beyond the intended memory boundary. To exploit this, an attacker must have local access to the system and be authenticated with at least low-level user privileges. Successful exploitation allows the attacker to disclose sensitive information from kernel memory. Microsoft has released security updates for various versions of Windows 10, Windows 11, and Windows Server 2012 to address this issue.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 Standard and Server Core

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats