Windows NTFS Elevation of Privilege Vulnerability

Plan PatchCVSS 7CVE-2026-50672Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A use-after-free vulnerability in Windows NTFS file system driver allows an authorized local user to elevate privileges. An attacker with a local user account can exploit this flaw to gain SYSTEM or Administrator-level access. The vulnerability affects Windows 10, Windows 11, and Windows Server 2019, 2022, and 2025 across multiple versions and architectures (32-bit, x64, ARM64). Microsoft has released fixes in the July 2026 security update for all affected versions.

What this means
What could happen
A user with local access to a Windows machine running NTFS can exploit a memory management flaw to gain elevated privileges (SYSTEM or Administrator), potentially allowing them to alter industrial software, access sensitive data, or disable safety-critical applications on that device.
Who's at risk
Organizations operating Windows 10, Windows 11, and Windows Server 2019/2022/2025 systems that are used for engineering workstations, HMI/SCADA clients, data historians, or operator stations. Affects both 32-bit and 64-bit systems as well as ARM-based variants and Server Core installations.
How it could be exploited
An attacker with a local user account on a Windows machine (such as a helpdesk, engineering, or operator workstation) exploits a use-after-free vulnerability in the NTFS file system driver to escalate privileges to Administrator or SYSTEM level. The attack requires local execution and an active user session but does not require social engineering or the user to take action.
Prerequisites
  • Local user account on the affected Windows system
  • Active user session or ability to execute code in user context
  • NTFS file system (default on Windows)
Requires local account accessLocal privilege escalation only (not remote)Low exploit probability (0.2% EPSS)Not actively exploitedRequires user interaction context
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (19)
19 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the July 2026 Windows security update for your Windows version (see fixed versions in affected products list)
Long-term hardening
0/2
HARDENINGRestrict local user account permissions to the minimum required for job function (apply principle of least privilege)
HARDENINGDisable unnecessary local administrator accounts and enforce MFA or strong passwords on remaining privileged accounts
API: /api/v1/advisories/15c1b038-36e3-4be3-b1f6-84b4f5177509

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows NTFS Elevation of Privilege Vulnerability | CVSS 7 - OTPulse