Junglewise Threat Intelligence

CVE-2026-71329: Microsoft Windows NTFS heap buffer overflow via physical access

CVE-2026-71329 · Severity: medium · CVSS 6.8 · Published 2026-09-08

Executive brief

Windows NTFS, the file system used by Windows operating systems to manage and organize stored data, contains a heap-based buffer overflow vulnerability. An attacker with physical access to a computer can exploit this flaw to execute arbitrary code with system-level privileges, potentially allowing complete compromise of the affected machine including data theft and system takeover.

Technical details

A heap-based buffer overflow exists in the Windows NTFS file system driver. The vulnerability is triggered when processing specially crafted NTFS metadata during file system operations. Exploitation requires physical access to the target system, limiting the attack surface to scenarios where an attacker can directly connect storage devices or physically interact with the machine. Successful exploitation allows arbitrary code execution with kernel privileges. Microsoft has released security updates to address this vulnerability.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats