Windows NTFS Remote Code Execution Vulnerability
Plan PatchCVSS 7.3CVE-2026-58640Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionRequired
Summary
A heap-based buffer overflow in Windows NTFS allows an authorized local user to execute arbitrary code if they interact with a specially crafted file. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 across 32-bit, x64, and ARM64 architectures. Exploitation requires local system access and user interaction with a malicious file; it does not grant remote code execution.
What this means
What could happen
A logged-in user could exploit a buffer overflow in Windows NTFS to run code with the privileges of that user account, potentially enabling lateral movement within your network or persistence on compromised systems.
Who's at risk
Windows IT administrators and OT engineers whose control systems or engineering workstations run Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025. Any system that requires local user accounts and processes file attachments or user-provided files is at risk.
How it could be exploited
An attacker with a local user account must interact with a malicious file (e.g., open a crafted document or trigger NTFS parsing) to trigger the heap buffer overflow in NTFS and execute arbitrary code on the system.
Prerequisites
- Local user account on the target system
- User interaction with a malicious file designed to trigger NTFS buffer overflow
- Access to the affected Windows or Server system
Requires local user accountRequires user interaction with malicious fileAffects multiple Windows versionsLow exploitation probability
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXPrioritize patching Windows Server 2016, 2019, and 2022 systems in your critical infrastructure
All products
HOTFIXApply Microsoft's July 2026 security update to all Windows 10, Windows 11, and Windows Server systems
Long-term hardening
0/2HARDENINGEducate users not to open suspicious files or attachments from untrusted sources
HARDENINGRestrict user account privileges to the minimum required for their role to limit the scope of code execution if exploited
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/995ac602-90ff-4032-b964-3c7e181364f2Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.