Windows NTFS Elevation of Privilege Vulnerability

Plan PatchCVSS 8CVE-2026-69875Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionRequired
Summary

A heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. The vulnerability requires valid user credentials and can lead to administrator-level access to affected systems.

What this means
What could happen
A user with network access and local credentials could exploit a flaw in Windows NTFS to gain administrator-level privileges on the system, potentially allowing them to modify system configuration, access sensitive data, or disrupt operations.
Who's at risk
IT managers running Windows on engineering workstations, SCADA servers, or HMI systems should prioritize this update. Particularly critical for facilities where Windows servers manage network file shares, data logging, or interact with control systems. Affects Windows 10, Windows 11, Windows Server 2019, Server 2022, and Server 2025 across all supported architectures.
How it could be exploited
An attacker with valid user credentials and network access to a Windows system could trigger a heap-based buffer overflow in the NTFS driver by sending specially crafted network requests. Successful exploitation would grant the attacker administrator privileges without user interaction.
Prerequisites
  • Valid user account credentials
  • Network access to the affected Windows system
  • Local or network-based ability to interact with NTFS file system operations
Requires valid user credentialsPrivilege escalation capabilityAffects widely deployed Windows versions
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (22)
22 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/10
Do now
0/1
HARDENINGRestrict network access to Windows systems to authorized users only through firewall rules and VPN controls
Schedule — requires maintenance window
0/9

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 and Server Core to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 and Server Core to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 and Server Core to Build 10.0.26100.33438 or later
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit and x64) to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 21H2 (all architectures) to Build 10.0.19044.7725 or later
HOTFIXUpdate Windows 10 Version 22H2 (all architectures) to Build 10.0.19045.7725 or later
HOTFIXUpdate Windows 11 Version 23H2 (all architectures) to Build 10.0.22631.7582 or later
HOTFIXUpdate Windows 11 Version 24H2 (all architectures) to Build 10.0.26100.9445 or later
HOTFIXUpdate Windows 11 Version 25H2 (all architectures) to Build 10.0.26200.9445 or later
API: /api/v1/advisories/8d8b971e-df4e-471b-86a3-0b55344c07d3

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.