Windows NTFS Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-56175Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Heap-based buffer overflow in Windows NTFS file system driver allows an authorized local user to elevate privileges. An attacker with a user account could craft malicious file system structures to trigger the overflow and execute code with administrator rights. Affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025. Exploitation is assessed as less likely. Patches are available for all affected versions.

What this means
What could happen
A user with local access to a Windows system could exploit a flaw in the NTFS file system to gain administrator privileges, allowing them to modify files, install unauthorized software, or disrupt normal operations on that machine.
Who's at risk
Windows Server administrators managing 2016, 2019, 2022, or 2025 systems, and organizations running Windows 10 or 11 on engineering workstations, office computers, or HMI/SCADA host systems. Impacts any system using NTFS file systems (virtually all modern Windows deployments).
How it could be exploited
An attacker with a user account on a Windows system could craft a malicious file or directory structure on an NTFS volume. When the system processes this, a buffer overflow in the NTFS driver executes arbitrary code with elevated privileges, giving the attacker full control of the machine.
Prerequisites
  • Local user account on the Windows system
  • Ability to create or modify files on an NTFS-formatted volume
  • No special permissions or credentials required beyond basic user access
Low complexity exploitationLow EPSS score (0.3%) - exploit development less likelyRequires local access - not directly exploitable over networkAffects all supported Windows versions across server and client platforms
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply Windows security updates for July 2026 (Build 10.0.17763.9020 for Server 2019, Build 10.0.20348.5386 for Server 2022, Build 10.0.26100.33158 for Server 2025, or corresponding builds for Windows 10/11 versions)
API: /api/v1/advisories/828c1d47-4021-4b0c-8331-850b32b7ab15

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows NTFS Elevation of Privilege Vulnerability | CVSS 7.8 - OTPulse