Windows NTFS Elevation of Privilege Vulnerability
Plan PatchCVSS 8.4CVE-2026-77503Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
An out-of-bounds read vulnerability in the Windows NTFS file system driver allows a local user to escalate privileges to administrator level. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 across 32-bit, x64, and ARM64 architectures. Microsoft has released fixes for all affected versions via the September 2026 security update.
What this means
What could happen
A local attacker with standard user privileges could exploit an out-of-bounds read in the Windows NTFS file system to gain administrator-level access, allowing them to modify critical system files, access sensitive data, or disable security controls on the server.
Who's at risk
This affects all Windows operating systems commonly used in municipal IT environments, including Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 across all architectures. While this is an IT/OS vulnerability rather than OT-specific, it poses a risk to any Windows-based servers or workstations that manage or connect to industrial control systems, SCADA networks, or data historian systems.
How it could be exploited
An attacker with a user account on the Windows system can craft a malicious file system operation that triggers an out-of-bounds memory read in the NTFS driver. By leveraging this flaw, the attacker escalates their privileges from standard user to administrator without requiring any special credentials or additional authentication.
Prerequisites
- Local user account on the Windows system
- Ability to execute file system operations
Local privilege escalationNo authentication required once on systemLow complexity exploitationAffects all supported Windows versions
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/2
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXPrioritize patching Windows Server 2019, Windows Server 2022, and Windows 11 systems that run critical infrastructure or data processing tasks
All products
HOTFIXApply Microsoft's September 2026 security update to all affected Windows systems
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/f3fa28f2-6db0-430a-85df-c2abd3dba089Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.