Windows NTFS Information Disclosure Vulnerability
MonitorCVSS 5.5CVE-2026-65784Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
An out-of-bounds read vulnerability in the Windows NTFS file system driver allows a local, authenticated user to disclose information from NTFS memory regions that should be inaccessible to them. This could expose sensitive data from the file system or kernel memory. The vulnerability requires valid local user credentials or interactive logon access and does not grant administrative privileges. Microsoft rates exploitation likelihood as unlikely but has released fixes for all affected Windows versions.
What this means
What could happen
An attacker with local access to a Windows system could read sensitive data from NTFS file system memory that they should not have permission to access, potentially exposing information from deleted files or system memory.
Who's at risk
IT and OT environments running Windows 10 or Windows Server 2016–2025. This affects any engineering workstations, HMI systems, data historian servers, or administrative computers that use Windows NTFS and are accessible to local users. While not a direct OT protocol vulnerability, compromised credentials or local access to these systems could enable further attacks on networked ICS devices.
How it could be exploited
An attacker must first obtain local user credentials or interactive access to the Windows system. Once logged in, they can exploit an out-of-bounds read vulnerability in the NTFS driver to access memory regions containing sensitive data. This does not require administrative privileges.
Prerequisites
- Local user account credentials or interactive logon access to the Windows system
- System must be running one of the affected Windows versions listed
Requires local access (not remotely exploitable from the network)Requires valid user credentials or interactive accessLow exploitation complexityAffects sensitive data disclosure (not system availability or integrity)Affects multiple generations of widely-deployed operating systems
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the August 2026 Windows security update to your Windows 10, Windows 11, and Windows Server systems
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/5ddee30c-bd39-4aea-b0de-83cc646972e6Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.