Windows NTFS Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-62797Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A heap-based buffer overflow vulnerability exists in Windows NTFS file system. An authorized local user could trigger the overflow through a crafted file system operation to gain administrative privileges. All Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 versions are affected. Microsoft has released security updates for all affected versions.

What this means
What could happen
A user with local access to a Windows computer or server could exploit a buffer overflow in the NTFS file system to gain administrative privileges, potentially allowing them to modify critical OT applications, alter data, or disable safety controls.
Who's at risk
OT operators running Windows workstations (for engineering, SCADA client access, or historian systems) and any Windows servers (domain controllers, file servers, or data gateways) used in industrial environments should apply the patch. This is particularly relevant for facilities using Windows-based engineering workstations or HMI systems.
How it could be exploited
An attacker with local user credentials logs into a Windows workstation or server, crafts a malicious file or file system operation that triggers a heap buffer overflow in NTFS, and uses the resulting memory corruption to execute code with system/administrative privileges.
Prerequisites
  • Local user account on the Windows system
  • Physical or remote access to a user session (e.g., via Remote Desktop)
  • Ability to interact with the file system
Requires local user credentialsRequires local system accessAffects core OS file systemPotential for privilege escalation
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Remediation & Mitigation
0/6
Schedule — requires maintenance window
0/6

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 to build 10.0.17763.9115 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to build 10.0.20348.5499 or later
All products
HOTFIXUpdate Windows 10 Version 1809 to build 10.0.17763.9115 or later
HOTFIXUpdate Windows 10 Version 21H2 to build 10.0.19044.7663 or later
HOTFIXUpdate Windows 10 Version 22H2 to build 10.0.19045.7663 or later
HOTFIXUpdate Windows 11 (all versions) to the August 2026 security update
API: /api/v1/advisories/2191e7b5-a9dd-491f-bb7b-1c1938e316b3

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.