ZeroHour

CVE-2026-68832

mass

Integer Overflow in Windows NTFS Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-68832 is an integer overflow/wraparound flaw (CWE-190) in the Windows NTFS driver, disclosed by Microsoft with a CVSS 3.1 base score of 7.8. The flaw is triggered by local file system operations that cause the integer handling error in NTFS, and an authorized attacker with limited privileges can exploit it without user interaction. Successful exploitation allows the attacker to elevate privileges locally, with high impact on confidentiality, integrity, and availability on the affected machine. Any Windows system using NTFS is potentially affected, though the source data does not specify affected Windows editions or version ranges, so defenders should consult Microsoft's advisory. As of now there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days (16th percentile), indicating no known active exploitation.

What to do: Apply Microsoft's current cumulative Windows security update for CVE-2026-68832 as soon as it is available, checking the Microsoft advisory for the specific affected editions and builds in your estate. Until patched, restrict unprivileged local code execution on sensitive hosts and monitor for emergence of a public PoC or CISA KEV listing. Because this is a local privilege escalation flaw, also prioritize patching endpoints and servers that combine unprivileged local users with other exploitable services, where it could be chained into full compromise.

Affected
Microsoft Windows (NTFS driver/file system)
Estimated exposure
mass≈1 billion+ Windows installations (NTFS is the default file system across Windows client and server deployments) — NTFS ships as the default file system on effectively all Windows desktops and servers, and Microsoft has publicly reported on the order of a billion-plus active Windows devices, though the exact set of vulnerable builds is not stated in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.