Junglewise Threat Intelligence

CVE-2026-77503: Microsoft Windows NTFS out-of-bounds read privilege escalation

CVE-2026-77503 · Severity: high · CVSS 8.4 · Published 2026-09-08

Executive brief

Windows NTFS, the file system that manages data storage on most Windows computers, contains a vulnerability that allows an attacker with local access to read memory outside of intended boundaries. An attacker can exploit this flaw to gain higher-level system privileges, potentially compromising the entire computer and any data stored on it.

Technical details

An out-of-bounds read vulnerability exists in the Windows NTFS driver, allowing an attacker to read memory beyond allocated boundaries. The vulnerability is exploitable locally and can be leveraged to achieve privilege escalation. The attack does not require user interaction or prior elevated privileges, making it a viable local privilege escalation vector. A patch has been released by Microsoft to address this issue.

Affected products

  • Microsoft Windows NTFS <UNKNOWN>

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory

References

Related threats