Junglewise Threat Intelligence

CVE-2026-72935: Microsoft Windows NTFS out-of-bounds read privilege escalation

CVE-2026-72935 · Severity: medium · CVSS 6.7 · Published 2026-09-08

Executive brief

Windows NTFS is the file system that manages data storage on Windows computers. An authenticated local user can exploit an out-of-bounds read vulnerability in NTFS to escalate their privileges on the system, potentially gaining administrative access and control over the entire machine.

Technical details

An out-of-bounds read vulnerability exists in the Windows NTFS file system driver. The vulnerability allows an authenticated local attacker to read memory beyond allocated buffer boundaries, potentially exposing sensitive data or system state. This information can then be leveraged to escalate privileges to SYSTEM or administrator level. The attack requires local access and valid user credentials; it is not remotely exploitable. Microsoft has released security patches to address this vulnerability through their standard security update process.

Affected products

  • Microsoft Windows NTFS Multiple Windows versions

Timeline

  • 2026-09-08: disclosed

References

Related threats