Windows NTFS Elevation of Privilege Vulnerability

Plan PatchCVSS 8CVE-2026-69332Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionRequired
Summary

An out-of-bounds read vulnerability in the Windows NTFS driver allows an authenticated user to read memory outside the intended boundaries of the NTFS kernel driver. By leveraging this vulnerability with valid logon credentials, an attacker could escalate their privileges over a network. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025. Microsoft has released patches for all affected versions in the 2026-Sep security update.

What this means
What could happen
A user with valid logon credentials could read memory outside the NTFS driver's allocated space, potentially allowing them to escalate privileges and gain higher-level access to the system. This could permit unauthorized changes to critical operational data or system configurations on servers and workstations.
Who's at risk
Windows Server administrators and IT staff managing Windows 10/11 and Windows Server 2016–2025 systems across enterprise networks. This affects any OT environment running Windows-based HMI (Human Machine Interface) systems, data servers, or engineering workstations that authenticate users over a network. Particular concern for organizations using Windows Server as a data aggregator or historian in manufacturing or utility environments.
How it could be exploited
An attacker with valid local or domain user credentials could craft a malicious NTFS file system operation that triggers an out-of-bounds read in the kernel driver. The attacker could then use information leaked from kernel memory to bypass security protections and execute code with elevated privileges on the compromised system.
Prerequisites
  • Valid user account credentials (domain or local)
  • Network access to a Windows system or ability to log in locally
  • Ability to interact with the NTFS file system (e.g., file creation or manipulation)
Low complexity attackRequires valid credentialsHigh CVSS score (8.0)Affects multiple Windows versions and server platformsEscalation of privilege vulnerability
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDRestrict local logon access to engineering workstations and critical servers using Group Policy or local security policy
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXPrioritize patching Windows Server 2019, 2022, and 2025 systems in your ICS/SCADA network
All products
HOTFIXApply the 2026-Sep Windows security update to all affected Windows systems
Long-term hardening
0/1
HARDENINGDisable unnecessary file sharing protocols and limit user permissions to required NTFS operations only
API: /api/v1/advisories/592a3d07-9c37-43af-b005-4825f042df4b

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.