Junglewise Threat Intelligence

CVE-2026-50668: Microsoft Windows NTFS heap overflow privilege escalation

CVE-2026-50668 · Severity: medium · CVSS 6.8 · Published 2026-07-14

Technologies: Microsoft Windows 10 Version 21H2, Microsoft Windows 10 Version 1607, Microsoft Windows 11 Version 24H2, Microsoft Windows 11 Version 26H1, Microsoft Windows 10 Version 1809, Microsoft Windows 10 Version 22H2, Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows 11, Microsoft Windows 11 Version 25H2. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Windows NTFS file system, which is responsible for managing how data is stored and retrieved on hard drives. An attacker with physical access to a computer could exploit this flaw to gain higher-level system permissions, potentially allowing them to access restricted files or take control of the device. This risk is primarily relevant for lost or stolen laptops and workstations where an unauthorized person can physically interact with the hardware.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists within the Windows NTFS driver. The flaw is triggered through a physical attack vector, likely involving the connection of a specially crafted storage device or manipulation of the file system at the hardware level. An attacker does not require prior administrative privileges or user interaction to trigger the overflow. Successful exploitation allows the attacker to achieve local privilege escalation (LPE), gaining SYSTEM-level access. Microsoft has released security updates to address this issue across various versions of Windows 10, Windows 11, and Windows Server.

Affected products

  • Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
  • Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
  • Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
  • Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
  • Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2525
  • Microsoft Windows Server 2016 10.0.14393.0 to 10.0.14393.9339

Timeline

  • 2026-07-14: advisory: Initial advisory published by Microsoft and NVD
  • 2026-07-14: patched: Security updates made available by Microsoft

References

Related threats