Executive brief
A security vulnerability has been identified in the Windows NTFS file system, which is responsible for managing how data is stored and retrieved on hard drives. An attacker who already has basic access to a system could exploit this flaw to gain higher-level permissions and execute unauthorized commands. This could lead to a full system compromise, allowing the attacker to view sensitive data or disrupt operations.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists in the Microsoft Windows NTFS driver. The flaw is triggered when the system improperly handles specific file system operations, leading to memory corruption. An attacker with local access and low-level privileges can exploit this by convincing a user to perform a specific action (User Interaction required), resulting in arbitrary code execution with elevated privileges. Microsoft has released security updates to address this issue across multiple versions of Windows and Windows Server.
Affected products
- Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 Versions 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All editions
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory