Windows NTFS Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-69265Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Out-of-bounds read in Windows NTFS filesystem allows a local authorized user to elevate privileges from standard user to administrator level. This vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025.
What this means
What could happen
An authorized user with local access to a Windows machine could exploit this NTFS vulnerability to escalate their privileges to administrator level, potentially allowing them to install malware, modify critical files, or take full control of the system.
Who's at risk
IT and OT environments running Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (all supported versions), Windows Server 2016, 2019, 2022, or 2025. This affects both general-purpose IT systems and any Windows-based industrial workstations, historian servers, engineering consoles, or data management systems in water utilities or electrical systems.
How it could be exploited
An attacker who already has a local user account on the machine exploits an out-of-bounds read in the NTFS filesystem driver to gain elevated (administrator) privileges without needing credentials or physical access.
Prerequisites
- Local user account with standard privileges on the affected Windows system
- Access to the NTFS filesystem on the machine
Local privilege escalationRequires existing user accountAffects multiple Windows versionsNTFS filesystem component vulnerableAffects workstations and servers both
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXApply the September 2026 Microsoft security update to Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2016, Windows Server 2019, Windows Server 2022, Windows Server 2025, or Windows 11 (all supported versions)
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/9853b8a0-74ab-4f5a-b0ff-5d4a381efa4eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.