Junglewise Threat Intelligence

CVE-2026-50388: Microsoft Windows NTFS out-of-bounds read

CVE-2026-50388 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A vulnerability exists in the Windows NTFS file system, which is the primary system used by Windows to store and retrieve files on hard drives. An attacker who successfully exploits this could gain the ability to run malicious code on a victim's computer. While the attack must be initiated locally, it could lead to a full system compromise, allowing unauthorized access to sensitive data or the disruption of business operations.

Technical details

This vulnerability is characterized as an out-of-bounds read (CWE-125) and integer underflow (CWE-191) within the Windows NTFS driver. The flaw is triggered when the system processes specially crafted NTFS file system metadata. Although the attack vector is local, the CVSS metric indicates that no prior privileges are required (PR:N), though user interaction (UI:R) is necessary—likely involving the mounting or accessing of a malicious storage device or disk image. Successful exploitation allows for local code execution with the potential for full system compromise. Microsoft has released security updates to address this issue across affected Windows 10, 11, and Server 2012 versions.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 All editions

Timeline

  • 2026-07-14: disclosed: Initial disclosure by Microsoft and NVD publication.
  • 2026-07-14: patched: Security updates made available by Microsoft.

References

Related threats