Windows NTFS Remote Code Execution Vulnerability

Plan PatchCVSS 7.8CVE-2026-49797Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

A heap-based buffer overflow in Windows NTFS file system handling allows a local user to execute arbitrary code with system privileges. The vulnerability is triggered through file system operations or by connecting malicious storage media. Exploitation is considered less likely in the wild, but patches are available for all supported Windows versions.

What this means
What could happen
A local attacker with user access could exploit a buffer overflow in NTFS to run commands with system privileges, potentially disrupting operations or gaining persistence on control system workstations or servers.
Who's at risk
This affects organizations running Windows 10, Windows 11, or Windows Server 2016–2025 on engineering workstations, operator consoles, data servers, and any other IT infrastructure that supports OT networks. Any facility with Windows-based SCADA workstations, historians, or administrative servers should prioritize patching.
How it could be exploited
An attacker with local user access to a Windows machine triggers the NTFS buffer overflow through specially crafted file system operations or by inserting a malicious storage device. This allows them to execute code with elevated privileges on that system.
Prerequisites
  • Local user access to the affected Windows system
  • Ability to perform file system operations or connect storage media
Low complexity exploitationRequires local user accessAffects IT infrastructure supporting OT operations
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXApply the 2026-Jul security update to all affected Windows systems (Windows 10, Windows 11, Windows Server 2016, 2019, 2022, 2025)
Long-term hardening
0/2
HARDENINGRestrict local user access to engineering workstations and servers; use role-based access control to limit who can log in
HARDENINGDisable or restrict USB ports and external storage on critical control system workstations if not operationally necessary
API: /api/v1/advisories/9c76904e-f374-480e-a8fd-e66949297f7f

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.