Windows NTFS Elevation of Privilege Vulnerability
Plan PatchCVSS 7.3CVE-2026-49789Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionRequired
Summary
A stack-based buffer overflow vulnerability in Windows NTFS allows an authorized local user to elevate privileges to administrative level. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 across all system architectures. Exploitation requires local user account access and user interaction to craft or trigger a malicious NTFS operation. Patches are available for all affected products.
What this means
What could happen
A local user with standard privileges could overflow a buffer in NTFS and gain administrative access to the Windows system, potentially allowing full control of the machine and any connected industrial equipment or data it manages.
Who's at risk
Windows 10 and Windows 11 systems (all versions and architectures including 32-bit, x64, and ARM64), Windows Server 2016, 2019, 2022, and 2025 installations. This affects any organization running these operating systems on engineering workstations, HMI servers, historian servers, or other Windows-based computers in industrial environments.
How it could be exploited
An attacker with a local user account must craft a malicious file or NTFS operation that triggers the stack-based buffer overflow in the NTFS driver. The overflow allows the attacker to overwrite the stack and execute code with elevated (administrative) privileges on the host system.
Prerequisites
- Local user account on the target Windows system
- File creation or modification ability on an NTFS-formatted volume
- User interaction (ability to interact with the crafted file or trigger NTFS operation)
Local privilege escalationLow attack complexityRequires valid user accountRequires user interaction
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXInstall the 2026-Jul Windows security update for your Windows version (apply the appropriate build number from the affected products list to ensure you are patched).
Long-term hardening
0/2HARDENINGApply principle of least privilege: remove or restrict local user accounts from systems that do not require them to perform job functions.
HARDENINGIsolate critical control system servers and workstations from general IT networks using firewall rules and network segmentation to limit lateral movement.
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/0b539bc4-e476-49dc-b30b-e908c92a38e6Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.