Windows NTFS Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-68832Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

An integer overflow vulnerability in Windows NTFS allows a user with a valid local account to escalate privileges to administrator level. The flaw exists in how NTFS handles certain file system operations and does not require special user interaction or network access. Microsoft rates exploitation as "Less Likely" and has released fixes for Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (all supported versions), Windows Server 2016, 2019, 2022, and 2025.

What this means
What could happen
An attacker with a low-privileged account on a Windows system could exploit an NTFS flaw to gain full system administrator access, potentially allowing them to disable monitoring, alter safety controls, or install persistent backdoors on your industrial network.
Who's at risk
Windows administrators and OT security staff managing Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems used as engineering workstations, HMIs, or supervisory control servers in water and electric utilities. Any Windows-based SCADA front-end, historian server, or domain controller is in scope.
How it could be exploited
An attacker with a valid low-privileged user account on a Windows server or workstation exploits an integer overflow in the NTFS file system to bypass access controls and escalate privileges to administrator level. This typically requires local access and the ability to execute code or manipulate file system objects on the vulnerable machine.
Prerequisites
  • Valid low-privileged user account on the affected Windows system
  • Local code execution capability or ability to manipulate file system objects
  • No remote exploitation possible—attacker must already have access to the machine
Low complexity exploitNo authentication bypass (requires valid account)Local privilege escalation onlyAffects all major Windows versions still in support
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/4
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply Microsoft September 2026 security update to all affected Windows systems
Long-term hardening
0/3
HARDENINGRestrict local user account creation and disable Guest accounts on engineering workstations and servers
HARDENINGImplement least-privilege account policies so operator and engineering accounts have only the minimum permissions needed for their roles
HARDENINGEnable Windows Defender Credential Guard on Windows 10 Version 21H2 and later, and Windows 11 systems to prevent credential theft from escalated processes
API: /api/v1/advisories/5d7436ad-9d41-4845-a6b8-212147d9ad6c

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows NTFS Elevation of Privilege Vulnerability | CVSS 7.8 - OTPulse