Windows NTFS Remote Code Execution Vulnerability

Plan PatchCVSS 7.3CVE-2026-58640Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionRequired
Summary

A heap-based buffer overflow in Windows NTFS allows an authorized local user to execute arbitrary code if they interact with a specially crafted file. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 across 32-bit, x64, and ARM64 architectures. Exploitation requires local system access and user interaction with a malicious file; it does not grant remote code execution.

What this means
What could happen
A logged-in user could exploit a buffer overflow in Windows NTFS to run code with the privileges of that user account, potentially enabling lateral movement within your network or persistence on compromised systems.
Who's at risk
Windows IT administrators and OT engineers whose control systems or engineering workstations run Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025. Any system that requires local user accounts and processes file attachments or user-provided files is at risk.
How it could be exploited
An attacker with a local user account must interact with a malicious file (e.g., open a crafted document or trigger NTFS parsing) to trigger the heap buffer overflow in NTFS and execute arbitrary code on the system.
Prerequisites
  • Local user account on the target system
  • User interaction with a malicious file designed to trigger NTFS buffer overflow
  • Access to the affected Windows or Server system
Requires local user accountRequires user interaction with malicious fileAffects multiple Windows versionsLow exploitation probability
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/4
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXPrioritize patching Windows Server 2016, 2019, and 2022 systems in your critical infrastructure
All products
HOTFIXApply Microsoft's July 2026 security update to all Windows 10, Windows 11, and Windows Server systems
Long-term hardening
0/2
HARDENINGEducate users not to open suspicious files or attachments from untrusted sources
HARDENINGRestrict user account privileges to the minimum required for their role to limit the scope of code execution if exploited
API: /api/v1/advisories/995ac602-90ff-4032-b964-3c7e181364f2

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.