Executive brief
A security vulnerability exists in the Windows NTFS file system, which is the primary system used by Windows to store and retrieve files on hard drives. An attacker could exploit this flaw to run malicious code on a target computer, potentially leading to a full system takeover or data theft. To carry out the attack, the intruder would typically need to trick a user into opening a specially crafted file or visiting a malicious site.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists in the Windows NTFS driver. The flaw is triggered when the system processes malformed NTFS metadata, leading to memory corruption in the heap. An attacker can exploit this by convincing a local user to interact with a malicious file or storage medium (User Interaction required). Successful exploitation allows for arbitrary code execution with the privileges of the current user or potentially elevated system privileges. Microsoft has released security updates to address this issue across affected Windows 10 and 11 versions.
Affected products
- Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
- Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
- Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
- Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
- Microsoft Windows 11 Version 23H2 10.0.22631.0 to 10.0.22631.7376
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 26H1 10.0.28000.0 to 10.0.28000.2525
Timeline
- 2026-07-14: disclosed: Initial publication by Microsoft and NVD
- 2026-07-14: patched: Security updates made available via Microsoft Update Guide