Windows NTFS Tampering Vulnerability
MonitorCVSS 4.7CVE-2026-69425Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary
Improper link resolution in Windows NTFS allows an authorized local user to tamper with files through symbolic link exploitation. An attacker with local user credentials can create a symbolic link to redirect file operations performed by higher-privilege processes, enabling unauthorized file modification. The vulnerability requires local system access and specific knowledge of target file paths.
What this means
What could happen
A local attacker with user-level credentials could modify files on an NTFS drive by exploiting symbolic link handling, potentially affecting critical files if the attacker has write access to directories containing them.
Who's at risk
Windows IT administrators and any organization running Windows 11 systems on x64 or ARM64 architecture, particularly those where engineering workstations or HMI systems run Windows 11 and handle sensitive process control files.
How it could be exploited
An attacker with local user account access creates a symbolic link pointing to a file they should not be able to modify. When a privileged process or application follows the link and writes to it, the attacker's target file gets modified instead. This requires the attacker to already have local system access and identify a writable directory that a higher-privilege process uses.
Prerequisites
- Local user account on the Windows system
- Write access to a directory that processes follow symbolic links from
- Knowledge of file paths that higher-privilege processes access
Requires local user credentialsHigh complexity attack requiring privileged process interactionLow EPSS score (0.3%)Affects file integrity only, not confidentiality or availability
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/2
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply Windows Update to the latest available build for your Windows 11 version (26200.9445 for 25H2, 22631.7582 for 23H2, 26100.9445 for 24H2, or 28000.2954 for 26H1)
Long-term hardening
0/1HARDENINGRestrict local user account creation and audit existing accounts to remove unnecessary local access
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/3c950936-8170-4f46-9414-2490977d827dGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.