Executive brief
Windows NTFS is the file system used by Windows operating systems to store and manage files. An authenticated attacker with network access can read data from memory areas outside the intended boundaries, potentially exposing sensitive information from the system. This vulnerability requires prior authentication and network connectivity to exploit.
Technical details
This is an out-of-bounds read vulnerability in the Windows NTFS file system implementation. An authenticated attacker with network access can trigger an out-of-bounds memory read operation, allowing them to disclose information from unintended memory regions. The vulnerability requires prior authentication to the system and network reachability. The attacker can achieve information disclosure but cannot directly execute code or modify files. Patches are available from Microsoft through their standard security update process.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed