Windows NTFS Elevation of Privilege Vulnerability

Plan PatchCVSS 7CVE-2026-69379Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A flaw in Windows NTFS file link handling allows a user with a local account to escalate privileges. The vulnerability exploits how the operating system resolves symbolic links and junctions during file access. An attacker could use this to gain unauthorized access to system-level resources or modify protected files. The issue affects Windows Server 2025 and Windows 11 (all recent versions on x64 and ARM64 architectures). Microsoft has released patches in the September 2026 security update for all affected versions.

What this means
What could happen
A user with local access to a Windows server or workstation could exploit a flaw in how NTFS handles file links to gain higher-level privileges (potentially system-level access), allowing them to modify critical files or configurations.
Who's at risk
This affects organizations running Windows Server 2025 or Windows 11 (versions 23H2, 24H2, 25H2, or 26H1) on any architecture. It is most relevant to mid-size IT environments where local workstations, office servers, or edge devices may have multiple users or where remote desktop access is common. The vulnerability does not directly target industrial control systems, but could affect SCADA engineer workstations, data historians running on Windows, or IT management systems integrated with water utilities or power facilities.
How it could be exploited
An attacker with a local user account on the system can craft a symbolic link or junction that points to a sensitive system file. When a privileged process follows this link during file access, the attacker can read or modify files they should not have access to, or inject code that runs with higher privileges.
Prerequisites
  • Local user account on the affected Windows system
  • Ability to create symbolic links or NTFS junctions in a directory the attacker can write to
  • A privileged process that accesses files in a predictable way that can be exploited
Low complexity attackRequires local user account (not no-authentication)Not actively exploitedLow EPSS score (0.3%)Vendor patches available
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (10)
10 with fix
ProductAffected VersionsFix Status
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 23H2 for ARM64-based SystemsAll versionsBuild 10.0.22631.7582
Windows 11 Version 23H2 for x64-based SystemsAll versionsBuild 10.0.22631.7582
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.9445
Windows 11 Version 24H2 for x64-based SystemsAll versionsBuild 10.0.26100.9445
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

Windows Server 2025
HOTFIXApply the September 2026 Windows security update to all affected Windows 11 and Windows Server 2025 systems
HARDENINGPrioritize patching Windows Server 2025 and Windows 11 systems that are exposed to untrusted users or allow local logons
Long-term hardening
0/1
HARDENINGReview and restrict local logon permissions on critical servers to limit the number of user accounts with interactive access
API: /api/v1/advisories/bab23be0-d736-4a56-a7d3-533ed1b8e43b

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.