Windows NTFS Remote Code Execution Vulnerability

Plan PatchCVSS 8.8CVE-2026-69461Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

Stack-based buffer overflow in Windows NTFS allows an attacker to execute code over a network. The vulnerability affects Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems. Exploitation requires user interaction with malicious network content. Microsoft has released patches for all affected versions.

What this means
What could happen
An attacker could send a specially crafted network request that exploits a buffer overflow in NTFS to run malicious code on a Windows computer or server with the same privileges as the system. This could allow unauthorized access to sensitive data, modification of files, or disruption of services running on that machine.
Who's at risk
This affects Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems used as OT workstations, engineering stations, historian servers, or SCADA client machines. Any Windows-based computer or server in your plant network that processes NTFS data could be vulnerable if not patched.
How it could be exploited
An attacker sends a malicious network packet targeting the NTFS stack buffer overflow. The attack requires user interaction (the victim must open or access the malicious content), but once triggered, the attacker gains code execution on the target system. This could affect OT workstations, engineering stations, or servers involved in process control or data management.
Prerequisites
  • Network access to the target Windows system
  • User interaction required (victim must open/access malicious content over network)
  • Target system running affected Windows version
remotely exploitablehigh CVSS score (8.8)user interaction requiredaffects multiple Windows versions
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to Windows systems from untrusted networks using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the 2026-Sep Windows security update to all affected systems
Long-term hardening
0/1
HARDENINGSegment OT workstations and engineering stations from general IT networks to restrict malicious network traffic
API: /api/v1/advisories/f1a23c8d-564a-4360-b310-8d4cf05841c5

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.