Windows NTFS Remote Code Execution Vulnerability

Plan PatchCVSS 7.8CVE-2026-50309Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A heap-based buffer overflow exists in the Windows NTFS file system driver. An authorized user with local file system write access could craft a malicious file or folder that causes a buffer overflow when processed by NTFS, allowing execution of arbitrary code at kernel level and complete system compromise.

What this means
What could happen
An authorized user with local access to a Windows system could run arbitrary code with system privileges by exploiting a buffer overflow in the NTFS file system driver. This could allow an attacker to take full control of the machine and any connected industrial control systems it manages.
Who's at risk
Windows operators running any version of Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 should evaluate this risk. Most critical for organizations using Windows computers to manage OT networks, PLCs, or HMI systems, or running Windows-based data historian and SCADA servers.
How it could be exploited
An attacker with a user account on the Windows system could craft a malicious file or folder in NTFS that triggers the buffer overflow when the file system processes it. This requires local file system write access and would execute code at the kernel level, giving the attacker complete system control.
Prerequisites
  • Valid user account on the affected Windows system
  • Local file system write access to an NTFS partition
  • No remote exploitation possible; attacker must have local account or physical access
Local access requiredUser privileges neededRequires valid account or physical accessAffects Windows servers used for critical infrastructure management
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/2
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the 2026-Jul security update from Microsoft for your Windows version
Long-term hardening
0/1
HARDENINGRestrict local user account creation and access to Windows servers running critical systems
API: /api/v1/advisories/c6431648-ccdf-4d6b-96fc-ebc823142335

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows NTFS Remote Code Execution Vulnerability | CVSS 7.8 - OTPulse