Windows NTFS Remote Code Execution Vulnerability

Plan PatchCVSS 7.8CVE-2026-50386Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

Heap-based buffer overflow in Windows NTFS allows local code execution without authorization. An attacker could run arbitrary commands with the privileges of the user who triggered the overflow.

What this means
What could happen
An attacker with local access to a Windows system could execute arbitrary code and potentially gain control of the machine. This could affect HMI workstations, engineering stations, or historian servers running on Windows.
Who's at risk
Windows IT staff should care about this vulnerability on all Windows systems, particularly HMI workstations, engineering stations, historian servers, and any SCADA-related computers running Windows Server 2016 and later or Windows 10 and 11. Compromised workstations could be used to modify process configurations or gain access to control systems.
How it could be exploited
An attacker would need local access to the system and could trigger the buffer overflow through a specially crafted file or interaction with the NTFS filesystem. The attacker would then execute code with the privileges of the affected user.
Prerequisites
  • Local access to the Windows system
  • User interaction required (must open or process a specially crafted file)
  • Privilege level of the triggering user
local code execution possibleuser interaction requiredlow complexity attackaffects desktop and server systems
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (24)
24 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXApply the July 2026 Windows security update to all affected systems
HOTFIXPrioritize patching HMI workstations, engineering stations, and historian servers that use Windows NTFS
Long-term hardening
0/1
HARDENINGRestrict local access to Windows systems by limiting who can log in locally and what files they can access
API: /api/v1/advisories/0bf4ed32-bd54-4a9c-bb72-c5a339e2db07

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.