Windows NTFS Remote Code Execution Vulnerability

Plan PatchCVSS 7.8CVE-2026-50388Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally. The vulnerability affects Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 across 32-bit, x64, and ARM64 architectures.

What this means
What could happen
An attacker with local access to a Windows system could execute arbitrary code with the privileges of the logged-in user, potentially gaining control of engineering workstations, HMI systems, or servers used for industrial process monitoring and control.
Who's at risk
This vulnerability affects Windows workstations and servers used in utility operations, including engineering workstations running SCADA clients, HMI systems, and data acquisition servers. Any Windows 10, 11, or Server 2016–2025 system is potentially vulnerable and should be prioritized based on its role in process control or monitoring.
How it could be exploited
An attacker must have local access to the target Windows system. They would trigger the out-of-bounds read condition in the NTFS driver through a specially crafted file operation or mounted file system, leading to code execution in the kernel or user-mode context depending on the specific exploitation technique.
Prerequisites
  • Local access to a Windows system running an affected version
  • User interaction (opening a file or accessing a malicious mount point)
  • No elevated privileges required initially
Affects common workstation and server platformsRequires local access (lower risk for air-gapped systems)Exploitation complexity lowNo patch available yet for some systems
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXApply the 2026-Jul security update to all Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems
API: /api/v1/advisories/f6c90dbb-1931-4d26-9c34-26b2f4b58568

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows NTFS Remote Code Execution Vulnerability | CVSS 7.8 - OTPulse