ZeroHour

CVE-2026-68841

mass

Heap-based buffer overflow in Windows NTFS enables local privilege escalation

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-68841 is a heap-based buffer overflow (CWE-122) in the Windows NTFS component, assigned by Microsoft with a CVSS 3.1 score of 7.8. It is triggered locally by an authorized (authenticated) user whose interaction with the NTFS driver causes a heap buffer overflow, rather than via network or pre-authentication attack paths. A successful exploit allows the attacker to elevate privileges on the local system, with the CVSS vector indicating high impact on confidentiality, integrity, and availability — typically meaning code execution with elevated (kernel or SYSTEM-level) rights. Any Windows system running the NTFS component is within the affected scope, though the available data does not specify affected Windows version ranges. There is currently no known exploitation, no public proof-of-concept, no entry in CISA's KEV, and EPSS assigns only a 0.2% probability of exploitation within 30 days.

What to do: Check Microsoft's security advisory for CVE-2026-68841 to identify affected Windows releases and apply the patched builds as soon as they are available. In the meantime, limit local logon rights on sensitive systems to trusted users, since exploitation requires an authenticated local attacker. Because there is no known exploitation or public PoC, prioritize patching within normal update cycles but monitor for new advisories or KEV listings.

Affected
Microsoft Windows (NTFS component)
Estimated exposure
mass≈1 billion+ Windows devices (NTFS is the default file system on Windows, which runs on roughly 1.4 billion devices worldwide) — NTFS ships as the default file system on essentially every Windows installation, so the potential attack surface spans the entire Windows installed base of well over a billion devices, though exploitation requires local authenticated…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.