Windows NTFS Remote Code Execution Vulnerability
Plan PatchCVSS 7.8CVE-2026-50309Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A heap-based buffer overflow exists in the Windows NTFS file system driver. An authorized user with local file system write access could craft a malicious file or folder that causes a buffer overflow when processed by NTFS, allowing execution of arbitrary code at kernel level and complete system compromise.
What this means
What could happen
An authorized user with local access to a Windows system could run arbitrary code with system privileges by exploiting a buffer overflow in the NTFS file system driver. This could allow an attacker to take full control of the machine and any connected industrial control systems it manages.
Who's at risk
Windows operators running any version of Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 should evaluate this risk. Most critical for organizations using Windows computers to manage OT networks, PLCs, or HMI systems, or running Windows-based data historian and SCADA servers.
How it could be exploited
An attacker with a user account on the Windows system could craft a malicious file or folder in NTFS that triggers the buffer overflow when the file system processes it. This requires local file system write access and would execute code at the kernel level, giving the attacker complete system control.
Prerequisites
- Valid user account on the affected Windows system
- Local file system write access to an NTFS partition
- No remote exploitation possible; attacker must have local account or physical access
Local access requiredUser privileges neededRequires valid account or physical accessAffects Windows servers used for critical infrastructure management
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/2
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the 2026-Jul security update from Microsoft for your Windows version
Long-term hardening
0/1HARDENINGRestrict local user account creation and access to Windows servers running critical systems
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/c6431648-ccdf-4d6b-96fc-ebc823142335Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.