Windows NTFS Information Disclosure Vulnerability

MonitorCVSS 5.7CVE-2026-69591Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionRequired
Summary

Out-of-bounds read vulnerability in Windows NTFS file system driver. An authorized attacker can disclose information from system memory by triggering the vulnerability through network access, affecting Windows 10, Windows 11, Windows Server 2019, 2022, and 2025. The vulnerability requires valid user credentials and user interaction to exploit. No unauthorized system modification or denial of service is possible. All affected versions have patches available from Microsoft.

What this means
What could happen
An authorized attacker can read sensitive information from Windows NTFS file system memory, potentially disclosing configuration files, credentials, or other data stored on affected systems. The impact is limited to information disclosure; no system modification or denial of service is possible.
Who's at risk
This vulnerability affects Windows workstations and servers used in utility environments, particularly those handling engineering workstations, data historian systems, or domain-joined systems that process sensitive configuration or operational data. Affected versions include Windows 10, Windows 11, Windows Server 2019, 2022, and 2025.
How it could be exploited
An attacker with valid user credentials can trigger an out-of-bounds read in the NTFS driver by accessing specially crafted file system structures over the network, causing memory contents to be exposed to the attacker's session.
Prerequisites
  • Valid Windows user account (local or domain)
  • Network access to the affected Windows system
  • User interaction required (UI action to trigger the vulnerability)
remotely exploitablerequires authenticationlow complexity exploitationinformation disclosure onlyno active exploitation reported
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (22)
22 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXApply the 2026-Sep security update for your Windows version: Windows 10 1809 (Build 10.0.17763.9245), Windows 10 21H2 (Build 10.0.19044.7725), Windows 10 22H2 (Build 10.0.19045.7725), Windows Server 2019 (Build 10.0.17763.9245), Windows Server 2022 (Build 10.0.20348.5622), Windows Server 2025 (Build 10.0.26100.33438), Windows 11 23H2 (Build 10.0.22631.7582), Windows 11 24H2 (Build 10.0.26100.9445), Windows 11 25H2 (Build 10.0.26200.9445), or Windows 11 26H1 (Build 10.0.28000.2954).
API: /api/v1/advisories/f6edcb31-8e3d-4cbc-a28e-84672c4d7d7e

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.