Windows NTFS Elevation of Privilege Vulnerability
Plan PatchCVSS 8CVE-2026-68838Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionRequired
Summary
Stack-based buffer overflow in Windows NTFS file system allows an authorized user to elevate privileges. The vulnerability exists in NTFS handling and can be exploited over a network by an attacker who already has standard user-level access. Microsoft has released fixes across all supported Windows versions.
What this means
What could happen
An attacker with a standard user account can exploit a stack buffer overflow in NTFS to gain system-level privileges, potentially allowing them to modify critical system settings, access sensitive data, or alter configurations on servers and workstations throughout your network.
Who's at risk
All Windows workstations and servers running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 are affected. This includes domain-joined computers, file servers, and engineering workstations used in utilities and industrial environments. Any system with NTFS storage accessed over a network is at risk.
How it could be exploited
An attacker who already has a standard user account on a Windows machine (through phishing, weak passwords, or prior compromise) could trigger the NTFS vulnerability over the network to escalate their privileges to system level. Once elevated, they could run commands with the highest privileges, including modifying other user accounts, disabling security controls, or accessing protected files.
Prerequisites
- Standard user account credentials on a Windows workstation or server
- Network access to the target Windows system
- Ability to interact with NTFS filesystem through network share or local access
Remotely exploitableRequires valid user credentialsLow complexity attackAffects both workstations and serversWide OS version coverage increases exposure
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/12
Schedule — requires maintenance window
0/11Patching may require device reboot — plan for process interruption
Windows Server 2022
HOTFIXFor Windows Server 2022, update to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXFor Windows Server 2025, update to Build 10.0.26100.33438 or later
All products
HOTFIXApply the 2026-Sep (September 2026) Windows security update to all affected systems
HOTFIXFor Windows 10 Version 1607 / Server 2016, update to Build 10.0.14393.9512 or later
HOTFIXFor Windows 10 Version 1809 / Server 2019, update to Build 10.0.17763.9245 or later
HOTFIXFor Windows 10 Version 21H2, update to Build 10.0.19044.7725 or later
HOTFIXFor Windows 10 Version 22H2, update to Build 10.0.19045.7725 or later
HOTFIXFor Windows 11 Version 23H2, update to Build 10.0.22631.7582 or later
HOTFIXFor Windows 11 Version 24H2, update to Build 10.0.26100.9445 or later
HOTFIXFor Windows 11 Version 25H2, update to Build 10.0.26200.9445 or later
HOTFIXFor Windows 11 Version 26H1, update to Build 10.0.28000.2954 or later
Long-term hardening
0/1HARDENINGRestrict user account privileges: ensure standard users do not have unnecessary administrative rights on workstations or servers
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/9d5e4429-3cd9-475f-bbb7-b50d22b0eca4Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.