Windows NTFS Remote Code Execution Vulnerability
Plan PatchCVSS 7.8CVE-2026-50471Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
Heap-based buffer overflow in Windows NTFS allows local code execution. An attacker with local access could exploit this vulnerability through NTFS operations to run arbitrary commands with the privileges of the user or system.
What this means
What could happen
An attacker with local access to a Windows system could execute arbitrary code and gain control of that machine, potentially compromising engineering workstations, HMI systems, or Windows-based ICS servers managing plant operations.
Who's at risk
Organizations running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 are affected, particularly those using these systems as engineering workstations, HMI servers, data historians, or other OT infrastructure management platforms. All processor architectures (32-bit, 64-bit, ARM64) are impacted.
How it could be exploited
An attacker with local access crafts a malicious NTFS file or mount operation that triggers the heap buffer overflow. When the system processes this NTFS operation, the overflow allows the attacker to execute arbitrary code with local user or system privileges.
Prerequisites
- Local access to the Windows system
- Ability to create or interact with NTFS files or perform mount operations
- User interaction or system-level access to trigger NTFS parsing
Requires local accessAffects core operating system componentImpacts multiple Windows versions
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDDisable unnecessary NTFS features or mount capabilities where possible
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply Microsoft July 2026 security update for your Windows version (see fixed versions above)
Long-term hardening
0/1HARDENINGRestrict local access to Windows systems to authorized personnel only
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/2cc217e4-684f-4a57-930a-4a980fbee0e1Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.