Windows NTFS Remote Code Execution Vulnerability

Plan PatchCVSS 8.4CVE-2026-49184Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A heap-based buffer overflow vulnerability in Windows NTFS allows an unauthorized local attacker to execute arbitrary code. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2, and 26H1 across 32-bit, x64, and ARM64 architectures), Windows 11 (versions 24H2, 25H2, and 26H1), Windows Server 2016, 2019, 2022, and 2025 (both standard and Server Core installations). Exploitation requires local access to the system and the ability to interact with the NTFS file system but no elevated privileges. Microsoft has released fixes for all affected products.

What this means
What could happen
A local attacker with no special privileges could run arbitrary code on a Windows computer or server through a heap buffer overflow in NTFS, potentially compromising system integrity and data confidentiality.
Who's at risk
Windows 10 (all recent versions including 1607, 1809, 21H2, 22H2, and 26H1) and Windows Server administrators (2016, 2019, 2022, 2025) should prioritize patching. Any organization running these Windows versions on workstations or servers needs to apply updates, particularly critical infrastructure operators if they depend on Windows-based HMIs, engineering workstations, or historian servers.
How it could be exploited
An attacker with local access to the device could trigger a heap buffer overflow in the NTFS file system driver by interacting with specially crafted files or file system operations, leading to arbitrary code execution with the privileges of the running process.
Prerequisites
  • Local access to the Windows system
  • No elevated privileges required
  • Ability to interact with NTFS file system (e.g., create or modify files)
Local code executionAffects all major Windows versionsNo authentication requiredLow complexity exploitation
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the 2026-Jul security update to all affected Windows systems
Long-term hardening
0/2
HARDENINGRestrict local user access to sensitive systems using account access controls and physical security measures
HARDENINGMonitor systems for unusual file system activity and unauthorized local access attempts
API: /api/v1/advisories/8178e38c-d830-455a-8119-62dc598a37df

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows NTFS Remote Code Execution Vulnerability | CVSS 8.4 - OTPulse