Windows NTFS Elevation of Privilege Vulnerability

Plan PatchCVSS 8CVE-2026-69505Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionRequired
Summary

An out-of-bounds memory read vulnerability in Windows NTFS allows an attacker with a local user account to elevate privileges to administrator. The vulnerability is in the NTFS file system driver and can be triggered through file I/O operations. Exploitation is assessed as unlikely; Microsoft recommends applying the 2026-Sep security update.

What this means
What could happen
A user with local account access could read sensitive memory data and gain administrator privileges on the system. This could allow an attacker to control any software running on the server, including HMI, SCADA clients, or historian systems.
Who's at risk
Water utilities and electric utilities running SCADA HMI systems, historians, or engineering workstations on Windows 10 or Windows Server (2016, 2019, 2022, 2025) should prioritize this patch. Any server with administrative control over PLCs, RTUs, or SCADA networks is at risk if compromised through this privilege escalation.
How it could be exploited
An attacker with a valid local user account on the system exploits an out-of-bounds memory read in the NTFS file system driver. By crafting malicious file system operations, the attacker leaks kernel memory, extracts privilege escalation information, and elevates to administrator/SYSTEM privileges without further credentials or user interaction.
Prerequisites
  • Valid local user account on the affected Windows system
  • Ability to execute file system operations or trigger NTFS file I/O
Low exploitation probability (0.8% EPSS)Requires valid local account (not unauthenticated)Affects all supported Windows operating systemsPrivilege escalation to administrator level
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/4
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXApply the 2026-Sep Microsoft security update to all affected Windows 10 and Windows Server systems
HOTFIXPrioritize patching Windows Server systems that host SCADA HMI, historian, or process control software
Long-term hardening
0/2
HARDENINGRestrict local account creation and access on critical control system servers to authorized personnel only
HARDENINGImplement local admin password management (LAPS) or equivalent to limit account credential exposure across the network
API: /api/v1/advisories/962f8ced-7dc5-4458-95d2-46cebdb2dac3

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows NTFS Elevation of Privilege Vulnerability | CVSS 8 - OTPulse