Windows NTFS Elevation of Privilege Vulnerability

Plan PatchCVSS 8.4CVE-2026-77503Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

An out-of-bounds read vulnerability in the Windows NTFS file system driver allows a local user to escalate privileges to administrator level. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 across 32-bit, x64, and ARM64 architectures. Microsoft has released fixes for all affected versions via the September 2026 security update.

What this means
What could happen
A local attacker with standard user privileges could exploit an out-of-bounds read in the Windows NTFS file system to gain administrator-level access, allowing them to modify critical system files, access sensitive data, or disable security controls on the server.
Who's at risk
This affects all Windows operating systems commonly used in municipal IT environments, including Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 across all architectures. While this is an IT/OS vulnerability rather than OT-specific, it poses a risk to any Windows-based servers or workstations that manage or connect to industrial control systems, SCADA networks, or data historian systems.
How it could be exploited
An attacker with a user account on the Windows system can craft a malicious file system operation that triggers an out-of-bounds memory read in the NTFS driver. By leveraging this flaw, the attacker escalates their privileges from standard user to administrator without requiring any special credentials or additional authentication.
Prerequisites
  • Local user account on the Windows system
  • Ability to execute file system operations
Local privilege escalationNo authentication required once on systemLow complexity exploitationAffects all supported Windows versions
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/2
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXPrioritize patching Windows Server 2019, Windows Server 2022, and Windows 11 systems that run critical infrastructure or data processing tasks
All products
HOTFIXApply Microsoft's September 2026 security update to all affected Windows systems
API: /api/v1/advisories/f3fa28f2-6db0-430a-85df-c2abd3dba089

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.