Windows NTFS Remote Code Execution Vulnerability
MonitorCVSS 6.8CVE-2026-71329Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorPhysical
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
A heap-based buffer overflow exists in the Windows NTFS filesystem driver that allows code execution with kernel privileges when a crafted NTFS volume is mounted. The vulnerability requires physical access to a storage device and has been assigned CVE-2026-71329 with CVSS 6.8. All major Windows versions from Server 2016 through Windows 11 are affected. Microsoft has released patches in the September 2026 security update.
What this means
What could happen
A physical attacker with access to a server or workstation's storage device could exploit a heap buffer overflow in NTFS to run code with system privileges, potentially compromising the integrity of the machine and any sensitive data it holds.
Who's at risk
Any organization running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 systems. Highest risk: unattended servers in shared facilities, field laptops used by contractors, kiosk systems, and any computers without physical security controls. This affects IT infrastructure that supports OT operations, engineering workstations, and data storage systems.
How it could be exploited
An attacker must have physical access to a storage device (internal hard drive, USB drive, etc.) connected to the system. They craft a malicious NTFS filesystem structure that triggers a heap buffer overflow when Windows parses it. When the device is connected or mounted, the overflow executes arbitrary code with kernel privileges.
Prerequisites
- Physical access to a storage device that will be connected to the affected Windows system
- The storage device must be mounted or accessed by the Windows system to trigger the vulnerability
Requires physical access to exploit (lower remote risk)Low EPSS score (0.3%) indicates minimal real-world exploitationNot actively exploited (KEV status: No)Affects confidentiality, integrity, and availability of the operating system
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Do now
0/1WORKAROUNDDisable USB ports on publicly accessible or kiosk systems if not required for operations
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXApply the September 2026 security update to all affected Windows systems (Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 per the fixed build versions listed)
Long-term hardening
0/2HARDENINGRestrict physical access to server and workstation hardware, particularly USB ports and storage bays, to authorized personnel only
HARDENINGImplement BIOS/UEFI boot integrity verification to prevent unauthorized firmware modifications that could bypass security controls
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/6dacef5e-a8ce-4b97-9842-f857e8f89ac8Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.