Windows NTFS Elevation of Privilege Vulnerability
An out-of-bounds read vulnerability in the Windows NTFS driver allows an authenticated user to read memory outside the intended boundaries of the NTFS kernel driver. By leveraging this vulnerability with valid logon credentials, an attacker could escalate their privileges over a network. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025. Microsoft has released patches for all affected versions in the 2026-Sep security update.
- Valid user account credentials (domain or local)
- Network access to a Windows system or ability to log in locally
- Ability to interact with the NTFS file system (e.g., file creation or manipulation)
Patching may require device reboot — plan for process interruption
/api/v1/advisories/592a3d07-9c37-43af-b005-4825f042df4bGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.