CVE-2026-68841
massHeap-based buffer overflow in Windows NTFS enables local privilege escalation
CVE-2026-68841 is a heap-based buffer overflow (CWE-122) in the Windows NTFS component, assigned by Microsoft with a CVSS 3.1 score of 7.8. It is triggered locally by an authorized (authenticated) user whose interaction with the NTFS driver causes a heap buffer overflow, rather than via network or pre-authentication attack paths. A successful exploit allows the attacker to elevate privileges on the local system, with the CVSS vector indicating high impact on confidentiality, integrity, and availability — typically meaning code execution with elevated (kernel or SYSTEM-level) rights. Any Windows system running the NTFS component is within the affected scope, though the available data does not specify affected Windows version ranges. There is currently no known exploitation, no public proof-of-concept, no entry in CISA's KEV, and EPSS assigns only a 0.2% probability of exploitation within 30 days.
What to do: Check Microsoft's security advisory for CVE-2026-68841 to identify affected Windows releases and apply the patched builds as soon as they are available. In the meantime, limit local logon rights on sensitive systems to trusted users, since exploitation requires an authenticated local attacker. Because there is no known exploitation or public PoC, prioritize patching within normal update cycles but monitor for new advisories or KEV listings.
| Microsoft Windows (NTFS component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.