Windows NTFS Information Disclosure Vulnerability
MonitorCVSS 5.5CVE-2026-68851Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A buffer over-read vulnerability in Windows NTFS allows an authorized local attacker to disclose sensitive information from memory. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server systems (2016, 2019, 2022, 2025). Microsoft has released patches for all affected versions. Exploitation is assessed as less likely and requires local system access with user-level credentials.
What this means
What could happen
An attacker with local access could read sensitive information from Windows NTFS file system memory that they shouldn't have access to. This is primarily an information disclosure risk and does not allow changes to files or operations.
Who's at risk
Windows administrators managing Windows 10, Windows 11, and Windows Server environments (2016 through 2025). This affects both standard and Server Core installations across 32-bit, 64-bit, and ARM64 architectures. Any system using NTFS file system is vulnerable.
How it could be exploited
An attacker with a local user account on the Windows system could trigger the NTFS buffer over-read to leak sensitive data from kernel memory. This requires being logged into the system locally and interacting with NTFS file operations.
Prerequisites
- Local user account credentials on the affected Windows system
- Ability to execute commands or interact with the file system locally
- Access to the physical system or remote desktop access with valid credentials
Local authentication requiredLow exploit probability (0.3% EPSS)Affects multiple Windows versionsNo active exploitation reported
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXPrioritize patching Windows Server 2016, 2019, 2022, and 2025 installations in your environment
All products
HOTFIXApply Microsoft's September 2026 security update to your Windows 10, Windows 11, and Windows Server systems
Long-term hardening
0/1HARDENINGRestrict local system access to authorized personnel only and review user account permissions
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/22091050-e395-44a2-828c-fb620687b4a6Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.