Windows NTFS Remote Code Execution Vulnerability

Plan PatchCVSS 7.8CVE-2026-50417Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Heap-based buffer overflow in Windows NTFS file system allows an authorized local user to execute arbitrary code with elevated privileges. The vulnerability exists across Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), and Windows Server (2016, 2019, 2022, 2025) on 32-bit, x64, and ARM64 systems. Exploitation is assessed as less likely; Microsoft has released patches in the July 2026 security update.

What this means
What could happen
An attacker with local access to a Windows machine could exploit a heap buffer overflow in NTFS to run arbitrary code with elevated privileges, potentially compromising process control systems or data on the machine.
Who's at risk
Windows 10 (all recent versions: 1607, 1809, 21H2, 22H2), Windows 11 (all versions: 24H2, 25H2, 26H1), and Windows Server systems (2016, 2019, 2022, 2025) running on 32-bit, x64, or ARM64 architectures. Organizations should prioritize patching servers used in control system environments, particularly those hosting HMI (Human-Machine Interface) software, historian databases, or engineering workstations that manage water/electric infrastructure.
How it could be exploited
An attacker needs to be logged in as a user (or have compromised user credentials) and then trigger the NTFS vulnerability—likely by interacting with a specially crafted file or storage operation—to overflow the heap buffer and execute code with system-level permissions.
Prerequisites
  • Local user account access or valid credentials
  • Ability to interact with NTFS file operations (e.g., file read, write, or system API calls)
Requires local user access (not remotely exploitable from network alone)Low to moderate attack complexity (requires crafted interaction)Affects all supported Windows versionsVendor fixes available for all affected products
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXApply Windows security update for July 2026 (or later) to all affected Windows 10, Windows 11, and Windows Server systems
HOTFIXPrioritize patching Windows Server systems (2016, 2019, 2022, 2025) that host industrial control system applications or data storage
Long-term hardening
0/1
HARDENINGRestrict local login access to Windows machines to authorized personnel only; disable unnecessary user accounts
API: /api/v1/advisories/1dfeee83-d645-4d9b-811a-1213d4334dfe

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows NTFS Remote Code Execution Vulnerability | CVSS 7.8 - OTPulse