Windows NTFS Remote Code Execution Vulnerability

Plan PatchCVSS 8.4CVE-2026-69479Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Heap-based buffer overflow in Windows NTFS filesystem driver allows unauthorized code execution with system privileges when an attacker has local access to the system. The vulnerability can be triggered through crafted file operations or filesystem interaction, potentially compromising the entire system and any connected networks or data it manages.

What this means
What could happen
A heap-based buffer overflow in Windows NTFS could allow an attacker with local access to execute arbitrary code with system privileges, potentially compromising the entire computer and any connected OT systems or data it manages.
Who's at risk
Organizations operating Windows-based engineering workstations, HMI servers, data historians, or administrative systems used to manage OT environments. This includes water authorities and electric utilities running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025.
How it could be exploited
An attacker with local access to a Windows machine could craft a malicious file or trigger specific NTFS operations that cause a buffer overflow in the NTFS driver, allowing arbitrary code execution at the kernel level. This could affect engineering workstations, HMI servers, or data historians that run Windows.
Prerequisites
  • Local access to the affected Windows system
  • Ability to interact with NTFS filesystem (e.g., create or manipulate files)
Requires local access to exploitHigh severity CVSS score (8.4)Affects all supported Windows versionsVendor patches available
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/7
Do now
0/1
WORKAROUNDRestrict local console and remote desktop access to Windows systems to authorized personnel only
Schedule — requires maintenance window
0/6

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate all Windows Server 2019 systems to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate all Windows Server 2022 systems to Build 10.0.20348.5622 or later
All products
HOTFIXUpdate all Windows 10 Version 1809 systems to Build 10.0.17763.9245 or later
HOTFIXUpdate all Windows 10 Version 21H2 systems to Build 10.0.19044.7725 or later
HOTFIXUpdate all Windows 10 Version 22H2 systems to Build 10.0.19045.7725 or later
HOTFIXUpdate all Windows 11 systems to their respective patched builds as listed in affected products
API: /api/v1/advisories/2f6947a9-d57e-48bc-9483-49c74c962465

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.