Windows NTFS Remote Code Execution Vulnerability
A heap-based buffer overflow vulnerability in Windows NTFS allows an unauthorized local attacker to execute arbitrary code. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2, and 26H1 across 32-bit, x64, and ARM64 architectures), Windows 11 (versions 24H2, 25H2, and 26H1), Windows Server 2016, 2019, 2022, and 2025 (both standard and Server Core installations). Exploitation requires local access to the system and the ability to interact with the NTFS file system but no elevated privileges. Microsoft has released fixes for all affected products.
- Local access to the Windows system
- No elevated privileges required
- Ability to interact with NTFS file system (e.g., create or modify files)
Patching may require device reboot — plan for process interruption
/api/v1/advisories/8178e38c-d830-455a-8119-62dc598a37dfGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.