Junglewise Threat Intelligence

CVE-2026-56182: Microsoft Windows NTFS privilege escalation via integer overflow

CVE-2026-56182 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Windows file system (NTFS) that could allow a user with basic access to a computer to gain full administrative control. By exploiting this flaw, an attacker who already has a foothold on a system can bypass security restrictions to access sensitive data or install malicious software. This issue affects various versions of Windows 10, Windows 11, and Windows Server.

Technical details

A privilege escalation vulnerability exists in the Microsoft Windows NTFS driver due to an integer overflow or wraparound condition (CWE-190). The flaw can lead to a heap-based buffer overflow (CWE-122) when the driver processes specially crafted file system requests. An attacker with local access and low-level user privileges can exploit this to execute code with SYSTEM privileges. The attack vector is local, requiring no user interaction, and has a high impact on confidentiality, integrity, and availability. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 Standard, Server Core

Timeline

  • 2026-07-14: advisory: Initial disclosure by Microsoft and NVD publication.
  • 2026-07-14: patched: Security updates made available via Microsoft Update Guide.

References

Related threats