Windows NTFS Tampering Vulnerability

MonitorCVSS 4.7CVE-2026-69425Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

Improper link resolution in Windows NTFS allows an authorized local user to tamper with files through symbolic link exploitation. An attacker with local user credentials can create a symbolic link to redirect file operations performed by higher-privilege processes, enabling unauthorized file modification. The vulnerability requires local system access and specific knowledge of target file paths.

What this means
What could happen
A local attacker with user-level credentials could modify files on an NTFS drive by exploiting symbolic link handling, potentially affecting critical files if the attacker has write access to directories containing them.
Who's at risk
Windows IT administrators and any organization running Windows 11 systems on x64 or ARM64 architecture, particularly those where engineering workstations or HMI systems run Windows 11 and handle sensitive process control files.
How it could be exploited
An attacker with local user account access creates a symbolic link pointing to a file they should not be able to modify. When a privileged process or application follows the link and writes to it, the attacker's target file gets modified instead. This requires the attacker to already have local system access and identify a writable directory that a higher-privilege process uses.
Prerequisites
  • Local user account on the Windows system
  • Write access to a directory that processes follow symbolic links from
  • Knowledge of file paths that higher-privilege processes access
Requires local user credentialsHigh complexity attack requiring privileged process interactionLow EPSS score (0.3%)Affects file integrity only, not confidentiality or availability
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 23H2 for ARM64-based SystemsAll versionsBuild 10.0.22631.7582
Windows 11 Version 23H2 for x64-based SystemsAll versionsBuild 10.0.22631.7582
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.9445
Windows 11 Version 24H2 for x64-based SystemsAll versionsBuild 10.0.26100.9445
Windows 11 version 26H1 for x64-based SystemsAll versionsBuild 10.0.28000.2954
Windows 11 Version 26H1 for ARM64-based SystemsAll versionsBuild 10.0.28000.2954
Remediation & Mitigation
0/2
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply Windows Update to the latest available build for your Windows 11 version (26200.9445 for 25H2, 22631.7582 for 23H2, 26100.9445 for 24H2, or 28000.2954 for 26H1)
Long-term hardening
0/1
HARDENINGRestrict local user account creation and audit existing accounts to remove unnecessary local access
API: /api/v1/advisories/3c950936-8170-4f46-9414-2490977d827d

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows NTFS Tampering Vulnerability | CVSS 4.7 - OTPulse