Junglewise Threat Intelligence

CVE-2026-68875: Microsoft Windows NTFS buffer over-read

CVE-2026-68875 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Windows NTFS. Vendors: Microsoft.

Executive brief

Windows NTFS is the default file system used by billions of Windows computers to store and manage files. A buffer over-read vulnerability allows a locally authenticated attacker to read sensitive memory contents and potentially execute code with system-level privileges, compromising the entire computer.

Technical details

A buffer over-read vulnerability exists in the Windows NTFS file system driver, where insufficient bounds checking allows an attacker to read data beyond the intended buffer boundary. The vulnerability requires local authentication and file system access to trigger. An attacker with local system access can exploit this flaw to leak kernel memory contents or escalate privileges, potentially achieving arbitrary code execution in the kernel context. Patches are available through Microsoft Security Updates.

Affected products

  • Microsoft Windows NTFS <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats