Windows NTFS Elevation of Privilege Vulnerability
A flaw in Windows NTFS file link handling allows a user with a local account to escalate privileges. The vulnerability exploits how the operating system resolves symbolic links and junctions during file access. An attacker could use this to gain unauthorized access to system-level resources or modify protected files. The issue affects Windows Server 2025 and Windows 11 (all recent versions on x64 and ARM64 architectures). Microsoft has released patches in the September 2026 security update for all affected versions.
- Local user account on the affected Windows system
- Ability to create symbolic links or NTFS junctions in a directory the attacker can write to
- A privileged process that accesses files in a predictable way that can be exploited
Patching may require device reboot — plan for process interruption
/api/v1/advisories/bab23be0-d736-4a56-a7d3-533ed1b8e43bGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.