Executive brief
Windows NTFS (the file system used by Windows) contains an integer overflow vulnerability that allows a user with local access to escalate their privileges to administrator level. An attacker who already has a user account on a system could exploit this to gain full control over the computer, potentially accessing sensitive data, installing malware, or disrupting operations.
Technical details
An integer overflow or wraparound vulnerability exists in the Windows NTFS file system driver. The vulnerability requires the attacker to already be authenticated as a local user on the system. By crafting specially-formed file system operations, an attacker can trigger the integer overflow condition to escape normal privilege boundaries and execute code with system-level privileges. This is a local privilege escalation attack vector that does not require network access or user interaction beyond the attacker's initial local access.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed