Windows NTFS Information Disclosure Vulnerability

MonitorCVSS 5.5CVE-2026-50341Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Buffer over-read vulnerability in Windows NTFS allows an authorized local attacker to read sensitive information from system memory. The vulnerability requires local logon access to exploit and results in information disclosure only, with no impact to system integrity or availability.

What this means
What could happen
An attacker with a user account on the system could read sensitive data from system memory, potentially exposing credentials or other confidential information. This is a local-only vulnerability with no direct impact to industrial control operations.
Who's at risk
Windows system administrators and IT staff managing Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems. This affects IT infrastructure used to manage or monitor industrial systems, though it does not directly impact PLCs, RTUs, or operational control devices.
How it could be exploited
An attacker with a valid local user account logs into the system and executes commands that trigger the NTFS buffer over-read, extracting sensitive information from kernel memory without administrative privileges required.
Prerequisites
  • Valid local user account on the Windows system
  • Local logon access (physical or remote desktop)
  • Ability to execute commands on the system
low complexityrequires local user authenticationaffects all Windows versions in support
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the July 2026 Windows security update to all affected systems. Identify your Windows version and architecture (32-bit, x64, or ARM64) and apply the corresponding build listed in the Microsoft advisory.
Long-term hardening
0/2
HARDENINGRestrict local logon access to trusted users only. Review and remove unnecessary local user accounts, and use group policy or access control lists to limit who can log into each system.
HARDENINGMonitor for suspicious local account activity and memory-access patterns. Log and alert on failed logon attempts and any use of debugging or memory-reading tools on critical systems.
API: /api/v1/advisories/d0de6795-84b0-4515-837d-07b6029ddefc

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows NTFS Information Disclosure Vulnerability | CVSS 5.5 - OTPulse