ZeroHour

CVE-2026-68838

mass

Stack Buffer Overflow in Windows NTFS Enables Network Privilege Escalation

CVSS 3.1
8.0 high
EPSS
<1%p34
Published
()
Modified
AI analysis

CVE-2026-68838 is a stack-based buffer overflow (CWE-121) in the NTFS component of Microsoft Windows. It can be triggered over a network by an authorized low-privileged attacker, and the CVSS vector (PR:L, UI:R) indicates valid credentials plus some user interaction are required; the published description does not specify the exact NTFS operation involved. A successful exploit allows the attacker to elevate privileges on the target with high impact on confidentiality, integrity, and availability. Any Windows system with NTFS volumes contains the affected component, but practical exploitability is limited to environments where low-privileged authorized users can reach the vulnerable code path over the network. Exploitation status: no public proof-of-concept, not listed in CISA KEV, and EPSS assigns a 0.4% probability of exploitation within 30 days, so no active exploitation is currently known.

What to do: Apply the Microsoft security update for CVE-2026-68838 through the normal Windows patch channel as soon as it is released, and consult Microsoft's advisory for the exact affected builds since no version range is provided here. Until patched, restrict low-privileged and untrusted accounts' network access to Windows hosts where feasible and watch Microsoft's advisory for signs of added exploitation.

Affected
Microsoft Windows NTFS
Estimated exposure
masshundreds of millions of Windows installations (NTFS is the default filesystem across the Windows install base) — NTFS ships as the default filesystem on essentially all Windows systems, whose install base is on the order of hundreds of millions of devices, though exploitation requires an authorized low-privileged user and user interaction.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-121
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.