Windows NTFS Remote Code Execution Vulnerability
Plan PatchCVSS 7.8CVE-2026-50494Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A heap-based buffer overflow exists in the Windows NTFS file system driver. An authenticated local attacker could exploit this vulnerability to execute code with kernel privileges. Microsoft has released patches for all supported Windows versions.
What this means
What could happen
A user with local access to a Windows system could trigger a buffer overflow in the NTFS file system driver, potentially allowing them to run code with elevated privileges and compromise the entire system.
Who's at risk
Windows IT administrators and OT personnel managing Windows-based systems used in industrial environments. This affects all versions of Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 across 32-bit, x64, and ARM64 architectures.
How it could be exploited
An attacker with a local user account could craft a malicious file or interact with the file system in a way that triggers the heap buffer overflow in NTFS kernel code. This could allow code execution in kernel mode, giving the attacker full system control.
Prerequisites
- Local user account on the Windows system
- Ability to interact with the NTFS file system (standard for any local user)
Local authentication requiredLow complexity exploitAll Windows versions affectedKernel-level code execution possible
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXApply the July 2026 Windows security update for your version (Build 10.0.17763.9020 for Windows Server 2019, Build 10.0.20348.5386 for Windows Server 2022, Build 10.0.26100.33158 for Windows Server 2025, or corresponding build numbers for Windows 10/11 versions)
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/877880c0-6f04-422a-8ae2-ff55c24e9255Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.