Windows NTFS Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-68841Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Heap-based buffer overflow in Windows NTFS allows an authorized attacker with local access to elevate privileges to SYSTEM or higher, potentially gaining full control of the device.
What this means
What could happen
An authenticated user on a server or workstation running Windows could exploit this to gain administrative privileges, allowing them to install software, modify configurations, or interfere with the operation of HMI systems, data historians, or engineering workstations that rely on Windows authentication and access controls.
Who's at risk
Water utilities and electric utilities running Windows on HMI servers, engineering workstations, data historians, or domain controllers should prioritize patching. This affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025. Any organization using Windows for industrial control systems, SCADA integration, or critical operational systems is at risk.
How it could be exploited
An attacker must have a local user account on the affected Windows system. They could then write a malicious file to an NTFS volume that triggers a heap buffer overflow when the NTFS driver processes it, escalating their privilege level to SYSTEM. This could be combined with phishing or social engineering to obtain initial credentials.
Prerequisites
- Local user account on the affected Windows system
- Ability to write files to an NTFS volume
- No administrative privileges required initially
Low attack complexityAffects multiple Windows versions and Server platformsNo authentication required after initial accessPatch available
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/10
Schedule — requires maintenance window
0/8Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXApply Microsoft security update for September 2026 to bring Windows Server 2019 systems to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXApply Microsoft security update for September 2026 to bring Windows Server 2022 systems to Build 10.0.20348.5622 or later
Windows Server 2016
HOTFIXApply Microsoft security update for September 2026 to bring Windows Server 2016 systems to Build 10.0.14393.9512 or later
Windows Server 2025
HOTFIXApply Microsoft security update for September 2026 to bring Windows Server 2025 systems to Build 10.0.26100.33438 or later
All products
HOTFIXApply Microsoft security update for September 2026 to bring Windows 10 Version 1809 systems to Build 10.0.17763.9245 or later
HOTFIXApply Microsoft security update for September 2026 to bring Windows 10 Version 21H2 systems to Build 10.0.19044.7725 or later
HOTFIXApply Microsoft security update for September 2026 to bring Windows 10 Version 22H2 systems to Build 10.0.19045.7725 or later
HOTFIXApply Microsoft security update for September 2026 to bring Windows 11 systems to the specified fixed builds (10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, or 10.0.28000.2954 depending on version)
Long-term hardening
0/2HARDENINGRestrict local user account creation on critical HMI servers, data historians, and engineering workstations to only authorized personnel
HARDENINGReview and enforce principle of least privilege for domain user accounts; disable unnecessary local administrator accounts
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/03640ce3-ce6d-4ecf-b8b4-9f355919156cGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.