Executive brief
Windows NTFS (the file system used by most Windows computers) contains an out-of-bounds read vulnerability that allows an authenticated attacker to elevate their privileges to a higher permission level over a network. An attacker with valid login credentials could exploit this flaw to gain administrator-level access without proper authorization, potentially compromising the entire system and accessing sensitive data.
Technical details
An out-of-bounds read vulnerability exists in the Windows NTFS file system driver. The vulnerability allows an authenticated attacker to read memory beyond the intended buffer boundaries, which can be leveraged to escalate privileges. The flaw requires network access and valid user credentials to exploit. A successful attack would grant the attacker elevated privileges on the target system. Microsoft has released security patches to address this vulnerability.
Affected products
- Microsoft Windows NTFS-affected versions
Timeline
- 2026-09-08: disclosed