Executive brief
Windows NTFS is the default file system for Windows operating systems, responsible for storing and managing all data on disk. A heap-based buffer overflow in NTFS could allow an authorized local user to run arbitrary code with elevated privileges, potentially compromising the entire system and any data stored on it.
Technical details
A heap-based buffer overflow vulnerability exists in the Windows NTFS file system driver. The vulnerability can be triggered by an authenticated local attacker with the ability to craft malicious input or file system operations. Exploitation allows arbitrary code execution in the kernel context. The attack requires local access and existing user credentials, making it a privilege escalation vector rather than a remote attack. A patch is expected from Microsoft; check MSRC for availability.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed