Windows NTFS Remote Code Execution Vulnerability
Plan PatchCVSS 7.8CVE-2026-50388Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally. The vulnerability affects Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 across 32-bit, x64, and ARM64 architectures.
What this means
What could happen
An attacker with local access to a Windows system could execute arbitrary code with the privileges of the logged-in user, potentially gaining control of engineering workstations, HMI systems, or servers used for industrial process monitoring and control.
Who's at risk
This vulnerability affects Windows workstations and servers used in utility operations, including engineering workstations running SCADA clients, HMI systems, and data acquisition servers. Any Windows 10, 11, or Server 2016–2025 system is potentially vulnerable and should be prioritized based on its role in process control or monitoring.
How it could be exploited
An attacker must have local access to the target Windows system. They would trigger the out-of-bounds read condition in the NTFS driver through a specially crafted file operation or mounted file system, leading to code execution in the kernel or user-mode context depending on the specific exploitation technique.
Prerequisites
- Local access to a Windows system running an affected version
- User interaction (opening a file or accessing a malicious mount point)
- No elevated privileges required initially
Affects common workstation and server platformsRequires local access (lower risk for air-gapped systems)Exploitation complexity lowNo patch available yet for some systems
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXApply the 2026-Jul security update to all Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/f6c90dbb-1931-4d26-9c34-26b2f4b58568Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.