Windows NTFS Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows NTFS file system processing allows a low-privileged authenticated attacker to escalate privileges to administrative level. The vulnerability is triggered when the operating system processes a specially crafted NTFS file or directory. An attacker with valid local credentials could exploit this to gain full control of the system. The flaw affects Windows 10 (all supported versions), Windows 11 (all supported versions), and Windows Server 2016 through 2025. Microsoft has released patches for all affected versions. Exploitation requires user interaction to process the malicious file, making widespread remote exploitation less likely but still feasible in targeted scenarios.
- Valid low-privileged local account credentials on the target Windows system
- Local or remote network access to interact with NTFS file operations
- User interaction to trigger file processing (e.g., opening a crafted file or folder)
Patching may require device reboot — plan for process interruption
/api/v1/advisories/2131e6c4-a87b-4e61-995f-09f05c3c3296Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.