Windows NTFS Information Disclosure Vulnerability

MonitorCVSS 4.6CVE-2026-61350Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorPhysical
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A buffer over-read vulnerability in the Windows NTFS file system driver allows an attacker with physical access to disclose information from system memory. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server 2016, 2019, 2022, and 2025. Microsoft has released patches for all affected versions.

What this means
What could happen
An attacker with physical access to a Windows system could read sensitive data from NTFS file system memory, potentially exposing confidential files or system information stored on disk.
Who's at risk
IT managers responsible for Windows 10 and Windows Server (2016, 2019, 2022, 2025) environments, particularly those with systems that require physical security controls. This is primarily a concern for on-premise systems where physical access controls are in place.
How it could be exploited
An attacker with physical access to a Windows system could trigger a buffer over-read in the NTFS file system driver by accessing specially crafted file system structures, allowing them to read memory contents that may contain sensitive data.
Prerequisites
  • Physical access to the Windows system
  • NTFS file system in use
requires physical accessinformation disclosureaffects multiple Windows versions
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the August 2026 Microsoft security update to your Windows 10 and Windows Server systems
API: /api/v1/advisories/e7e44d9b-aba1-48c2-9309-0334c1d438b6

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.