Windows NTFS Remote Code Execution Vulnerability
Plan PatchCVSS 7.8CVE-2026-50448Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
Heap-based buffer overflow in Windows NTFS file system allows an unauthorized attacker to execute code locally. The vulnerability is triggered when a user opens a malicious file, potentially on removable media or a network share. Successful exploitation allows the attacker to run arbitrary code in the security context of the user who accessed the file.
What this means
What could happen
A user on a Windows machine could trigger a heap memory overflow by opening a malicious file, allowing an attacker to run arbitrary code with the privileges of the logged-in user. On an OT workstation or engineering station, this could lead to unauthorized modification of control system configurations, data theft, or system compromise.
Who's at risk
Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems in any role (32-bit, x64, ARM64 architectures). This affects OT facilities that run engineering workstations, historian servers, HMI machines, or any Windows-based device connected to or adjacent to control networks where users access files or removable media.
How it could be exploited
An attacker crafts a malicious file or storage media that, when opened or accessed by a user on a Windows system, triggers the NTFS buffer overflow. The overflow allows code execution in the context of the user who accessed the file. On an engineering workstation or HMI connected to control systems, this could be leveraged to install backdoors or alter system settings.
Prerequisites
- User interaction required—a local user must open or access the malicious file
- Local or removable media access to the Windows system
- Standard user privileges (no elevated access needed to trigger vulnerability)
Requires user interactionLocal attack vector onlyLow EPSS score (0.3%)Not actively exploited
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/2WORKAROUNDUntil patched, restrict or monitor access to removable media and file shares from untrusted sources on OT workstations and engineering stations
HARDENINGEducate users not to open files from untrusted sources on engineering workstations and control room computers
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate Windows systems to the July 2026 security patch or later for your OS version (check Affected Products list for specific build numbers)
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/b109025d-6e1f-4558-9f7b-a94aaf146efcGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.