Junglewise Threat Intelligence

CVE-2026-68851: Microsoft Windows NTFS buffer over-read

CVE-2026-68851 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows NTFS is the file system used by Windows operating systems to store and organize files on storage devices. A buffer over-read vulnerability allows an authenticated local user to read sensitive information from the system's memory that they should not be able to access, potentially exposing confidential data like passwords, encryption keys, or other system secrets.

Technical details

This vulnerability is a buffer over-read in the Windows NTFS file system driver. The flaw allows an authenticated local attacker to read beyond allocated buffer boundaries in kernel memory, potentially disclosing sensitive information. The attack requires local system access and valid user credentials. An attacker can exploit this by issuing specially crafted file system requests to trigger the out-of-bounds read and extract data from kernel memory. A fix is available from Microsoft through security updates.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats