Windows NTFS Information Disclosure Vulnerability

MonitorCVSS 5.5CVE-2026-69504Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

An out-of-bounds read vulnerability in Windows NTFS allows an authorized local attacker to disclose information that they should not normally have access to. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server (2016, 2019, 2022, 2025) systems.

What this means
What could happen
An attacker with local access to a Windows system could read sensitive information stored on the NTFS file system that they are not normally authorized to access. This could expose operational data, configuration files, or other sensitive content stored on the server.
Who's at risk
Organizations running Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), or Windows Server (2016, 2019, 2022, 2025) are affected. This includes both standard and Server Core installations. ICS environments using Windows-based engineering workstations, HMI servers, or data aggregation systems should be prioritized.
How it could be exploited
An attacker with a valid local user account on a Windows system could exploit an out-of-bounds read vulnerability in NTFS to access file system data beyond their authorized permissions. This requires the attacker to run code or commands on the system locally.
Prerequisites
  • Valid local user account on the Windows system
  • Ability to execute commands or code locally on the affected Windows system
Low complexity attackRequires valid local credentialsAffects confidentiality only (no code execution or system modification)
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the September 2026 Windows security update to affected Windows 10 and Windows Server systems
Long-term hardening
0/2
HARDENINGRestrict local login access to Windows servers to only authorized administrators and service accounts
HARDENINGMonitor and audit local account creation and privilege escalation activities on Windows servers
API: /api/v1/advisories/52cc0375-bf0e-463e-9cd6-7aebdc2a3db1

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows NTFS Information Disclosure Vulnerability | CVSS 5.5 - OTPulse