Windows NTFS Remote Code Execution Vulnerability

Plan PatchCVSS 7.8CVE-2026-68875Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A buffer over-read vulnerability in Windows NTFS file system allows an authorized local attacker to execute arbitrary code. The vulnerability requires local login credentials and interaction with a specially crafted NTFS file or directory. Microsoft has released patches for all supported Windows versions (Server 2016 through 2025, Windows 10, and Windows 11) as part of the September 2026 security update.

What this means
What could happen
An attacker with local access to a Windows system could exploit a buffer over-read in NTFS to execute arbitrary code with the privileges of the user who triggered the vulnerability, potentially compromising the integrity of data or control logic on engineering workstations or HMI servers.
Who's at risk
Windows servers and workstations used as engineering stations, HMI servers, data servers, or administrative consoles in water utilities and electric utilities. This includes Windows Server 2016, 2019, 2022, and 2025 installations, as well as Windows 10 and Windows 11 systems used by field technicians or in control rooms.
How it could be exploited
An attacker with local logon credentials must interact with a specially crafted NTFS file or directory to trigger a buffer over-read condition. Once triggered, the attacker can execute code in the context of the user running the operation, allowing them to modify files, steal credentials, or pivot to other systems.
Prerequisites
  • Local login credentials required
  • Ability to interact with NTFS filesystem (read/write/execute files)
  • Specially crafted NTFS file or directory must be accessed
Requires local accessLow complexity attackAffects Windows infrastructure used in OT environmentsExploitation unlikely per vendor assessment
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/4
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXPrioritize patching Windows Server 2019, 2022, and 2025 systems in your control center and engineering workstations
All products
HOTFIXApply Microsoft September 2026 security update to all Windows systems
Long-term hardening
0/2
HARDENINGRestrict local logon access on critical HMI and engineering workstations to authorized personnel only
HARDENINGDisable local logon for service accounts and implement credential management to reduce the number of local user accounts with interactive access
API: /api/v1/advisories/8969b6f8-82bd-43f4-973c-f5b494556e7c

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.