Windows NTFS Information Disclosure Vulnerability
MonitorCVSS 4.6CVE-2026-61350Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorPhysical
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
A buffer over-read vulnerability in the Windows NTFS file system driver allows an attacker with physical access to disclose information from system memory. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server 2016, 2019, 2022, and 2025. Microsoft has released patches for all affected versions.
What this means
What could happen
An attacker with physical access to a Windows system could read sensitive data from NTFS file system memory, potentially exposing confidential files or system information stored on disk.
Who's at risk
IT managers responsible for Windows 10 and Windows Server (2016, 2019, 2022, 2025) environments, particularly those with systems that require physical security controls. This is primarily a concern for on-premise systems where physical access controls are in place.
How it could be exploited
An attacker with physical access to a Windows system could trigger a buffer over-read in the NTFS file system driver by accessing specially crafted file system structures, allowing them to read memory contents that may contain sensitive data.
Prerequisites
- Physical access to the Windows system
- NTFS file system in use
requires physical accessinformation disclosureaffects multiple Windows versions
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the August 2026 Microsoft security update to your Windows 10 and Windows Server systems
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/e7e44d9b-aba1-48c2-9309-0334c1d438b6Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.