Windows NTFS Remote Code Execution Vulnerability

Plan PatchCVSS 7.8CVE-2026-50313Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

A heap-based buffer overflow in Windows NTFS allows a local attacker to execute arbitrary code. The vulnerability exists in all supported versions of Windows 10, Windows 11, and Windows Server 2016 through 2025. Exploitation requires local access and user interaction; the attacker could gain code execution with the privileges of the user who accessed the malicious file or NTFS structure. Microsoft rates exploitation as "Less Likely" and recommends applying the 2026-Jul security update.

What this means
What could happen
A local attacker could execute arbitrary code on the machine with the same privileges as the user who triggered the vulnerability, potentially compromising data, installing malware, or disrupting operations if the affected Windows system controls industrial processes or hosts critical OT applications.
Who's at risk
Water utilities, electric utilities, and other critical infrastructure operators using Windows 10 or Windows Server (2016, 2019, 2022, 2025) should prioritize patching systems that host SCADA front-ends, historian databases, HMI workstations, or any OT network services. Particular attention should be paid to engineering workstations and operator consoles that interact with USB drives, network file shares, or external storage, which are common attack vectors in industrial environments.
How it could be exploited
An attacker with local access to the system could craft a malicious file or manipulate NTFS structures that, when accessed by a user, triggers the heap buffer overflow in the NTFS driver. The attacker could then execute code in the context of that user, or potentially escalate privileges if the user has elevated rights.
Prerequisites
  • Local access to the affected Windows system
  • User interaction required (user must access or open a malicious file or directory)
  • Attacker does not need credentials; user privileges determine the attack impact
Requires user interaction (reduces risk but not eliminates it in OT environments where USB devices are common)Local access required (but shared workstations and network shares increase exposure)Affects widely deployed Windows versions across IT and OT networksNo authentication required once attacker has local access
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/11
Schedule — requires maintenance window
0/11

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9339 or later
Windows Server 2019
HOTFIXUpdate Windows Server 2019 (including Server Core) to Build 10.0.17763.9020 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5386 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 (including Server Core) to Build 10.0.26100.33158 or later
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit and x64) to Build 10.0.17763.9020 or later
HOTFIXUpdate Windows 10 Version 1607 (32-bit and x64) to Build 10.0.14393.9339 or later
HOTFIXUpdate Windows 10 Version 21H2 to Build 10.0.19044.7548 or later
HOTFIXUpdate Windows 10 Version 22H2 to Build 10.0.19045.7548 or later
HOTFIXUpdate Windows 11 Version 24H2 to Build 10.0.26100.8875 or later
HOTFIXUpdate Windows 11 Version 25H2 to Build 10.0.26200.8875 or later
HOTFIXUpdate Windows 11 Version 26H1 to Build 10.0.28000.2269 (x64) or Build 10.0.28000.2525 (ARM64) or later
API: /api/v1/advisories/6be0f768-13f8-481d-987c-518070e056db

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows NTFS Remote Code Execution Vulnerability | CVSS 7.8 - OTPulse