Junglewise Threat Intelligence

CVE-2026-83995: Microsoft Windows NTFS heap buffer overflow privilege escalation

CVE-2026-83995 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

A heap buffer overflow vulnerability in Windows NTFS file system allows an authenticated local user to crash the system or execute arbitrary code with elevated privileges. This could allow an attacker to take complete control of an affected computer.

Technical details

A heap-based buffer overflow vulnerability exists in the Windows NTFS file system driver. The vulnerability requires local system access and valid user credentials to exploit. An attacker can craft a malicious file or trigger a specific NTFS operation to overflow a heap buffer, potentially leading to code execution in kernel mode or system denial of service. A patch is expected to be available from Microsoft.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats