Windows NTFS Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-50412Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Stack-based buffer overflow in Windows NTFS allows an authorized attacker with local access to escalate privileges. This affects Windows 10, Windows 11, and Windows Server 2016 through 2025 across 32-bit, x64, and ARM64 architectures.
What this means
What could happen
An attacker with local access to a Windows system could exploit a buffer overflow in NTFS to run commands with system privileges, potentially compromising control systems or engineering workstations that support your operational network.
Who's at risk
This affects all versions of Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025. Prioritize patching any Windows systems that serve as HMI interfaces, engineering workstations, data historians, or servers that support your OT network. Workstations used by control room operators or remote access points are especially critical.
How it could be exploited
An attacker must have local user credentials to log in to the Windows system. Once logged in, they could trigger the NTFS buffer overflow through a specially crafted file operation to escalate privileges and gain system-level access.
Prerequisites
- Local user account credentials on the Windows system
- Ability to perform file operations on NTFS volumes
- System must be running an unpatched version of Windows
Requires local credentialsLow attack complexityCan affect OT support systemsNo active exploitation reported
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
HOTFIXApply the July 2026 Microsoft security update to all Windows systems
HOTFIXPrioritize patches for Windows systems supporting operational technology or engineering workstations
Long-term hardening
0/1HARDENINGRestrict local login access to Windows systems to only necessary personnel
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/859cafbe-7de0-4b20-a517-7c946c0591bfGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.