Executive brief
Windows NTFS (New Technology File System) is the core file storage system used by Windows operating systems. An out-of-bounds read vulnerability in NTFS could allow an authenticated user with local access to escalate their privileges to administrator level, potentially compromising the entire system and enabling unauthorized access to sensitive data or malware installation.
Technical details
The vulnerability is an out-of-bounds read in the Windows NTFS file system component, triggered by specific file system operations. An authorized attacker with local access can craft a malicious NTFS structure or file to trigger the memory access violation, leading to information disclosure or privilege escalation. The attack requires local system access and existing user credentials. No remote exploitation vector is present. A security patch addressing this issue is expected to be available through Microsoft's standard update channels.
Affected products
- Microsoft Windows NTFS
Timeline
- 2026-09-08: disclosed