Executive brief
Windows NTFS is the default file system used by most Windows computers. A heap-based buffer overflow vulnerability allows an attacker with physical access to execute arbitrary code, potentially gaining full control of the system and accessing sensitive files or data stored on the drive.
Technical details
A heap-based buffer overflow exists in the Windows NTFS file system driver. The vulnerability is triggered during NTFS metadata processing and can be exploited via maliciously crafted file system structures. Physical access to the machine is required to exploit this flaw, such as by connecting a compromised storage device or modifying the file system on disk. Successful exploitation allows arbitrary code execution with kernel-level privileges. A patch is likely available through Microsoft's regular security updates.
Affected products
- Microsoft Windows NTFS <UNKNOWN>
Timeline
- 2026-09-08: disclosed