ZeroHour

CVE-2026-68834

mass

Stack-Based Buffer Overflow in Windows NTFS Allows Network Privilege Escalation

CVSS 3.1
8.0 high
EPSS
<1%p45
Published
()
Modified
AI analysis

CVE-2026-68834 is a stack-based buffer overflow (CWE-121) in the NTFS filesystem component of Microsoft Windows, with the CVE assigned by Microsoft ([email protected]). Per the CVSS 3.1 vector, it is reachable over a network and triggered by an authorized attacker who already holds low privileges, with user interaction required, meaning the vulnerable NTFS code path is reached through an action taken by a logged-on user rather than by a fully unauthenticated remote attacker. Successful exploitation allows the attacker to elevate privileges to a higher-privileged context, with high impact on confidentiality, integrity, and availability on the affected system. All Windows systems running the affected NTFS code are potentially exposed; the available data does not enumerate specific affected builds or versions, so defenders should consult Microsoft's advisory for exact ranges. There is no known public proof-of-concept, the issue is not in CISA's KEV, and EPSS places the 30-day exploitation probability at 0.6% (45th percentile), so no in-the-wild exploitation is currently known.

What to do: Check Microsoft's security advisory for CVE-2026-68834 to confirm which Windows builds are affected and apply the corresponding Windows security update from Microsoft's monthly release when it becomes available. Until patched, prioritize hosts where low-privileged users interact with NTFS over network paths (e.g., file servers and remote desktop/session hosts) and restrict interactive network access to sensitive volumes. Given no public PoC or KEV listing, routine patch-cycle handling with monitoring of Microsoft advisories is reasonable.

Affected
Microsoft Windows (NTFS component)
Estimated exposure
mass≈ hundreds of millions of Windows endpoints and servers (NTFS is the default filesystem on essentially all Windows installations) — Windows is the dominant desktop OS and is ubiquitous in enterprise server fleets, and NTFS is its standard filesystem, so any affected build implies an installed base in the hundreds of millions.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-121
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.