Windows NTFS Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-50422Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

An out-of-bounds read vulnerability in the Windows NTFS file system allows an authorized local user to escalate privileges to SYSTEM level. The vulnerability affects Windows 10 (all versions), Windows 11, Windows Server 2016, 2019, 2022, and 2025 on 32-bit, x64, and ARM64 architectures. Exploitation is assessed as less likely but still requires patching.

What this means
What could happen
An attacker with a local user account on a Windows system can exploit an NTFS flaw to gain administrator-level privileges, potentially allowing them to modify critical system files or reconfigure security policies.
Who's at risk
All organizations running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 on any architecture (32-bit, x64, or ARM64). This includes HMI workstations, engineering computers, and any Windows-based servers used for SCADA, data logging, or network services in water utilities or electrical systems.
How it could be exploited
An attacker with an existing local user account (such as a service account or unprivileged user) can trigger an out-of-bounds read in the NTFS file system driver through a crafted file system operation. By exploiting this flaw, the attacker escalates their privileges to SYSTEM or Administrator level without requiring administrator credentials or additional authentication.
Prerequisites
  • Local user account on the affected Windows system
  • No additional elevated credentials required
  • File system access to trigger the NTFS operation
Local privilege escalationLow attack complexityNo special privileges required to triggerAffects all active Windows versions and server platforms
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/7
Schedule — requires maintenance window
0/7

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9020 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5386 or later
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit) to Build 10.0.17763.9020 or later
HOTFIXUpdate Windows 10 Version 1809 (x64) to Build 10.0.17763.9020 or later
HOTFIXUpdate Windows 10 Version 21H2 to Build 10.0.19044.7548 or later
HOTFIXUpdate Windows 10 Version 22H2 to Build 10.0.19045.7548 or later
HOTFIXUpdate Windows 11 Version 24H2 and 25H2 to the corresponding fixed builds (10.0.26100.8875 or 10.0.26200.8875)
API: /api/v1/advisories/53e6e6b6-8f10-4c93-8daa-e6696fa50706

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows NTFS Elevation of Privilege Vulnerability | CVSS 7.8 - OTPulse