ZeroHour

CVE-2026-68875

mass

Buffer over-read in Windows NTFS enables local code execution

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-68875 is a buffer over-read (CWE-126) in the NTFS filesystem component of Microsoft Windows. Per the CVSS vector (AV:L/AC:L/PR:L/UI:N), an authorized attacker with low privileges on the system can trigger the flaw locally, with no user interaction required. Successful exploitation yields local code execution with high impact to confidentiality, integrity, and availability; because NTFS is implemented in kernel mode, this plausibly permits full system compromise, though Microsoft's description does not explicitly label it privilege escalation. Practically, risk is concentrated on Windows systems where an untrusted or lower-privileged user can run code. There is currently no public proof-of-concept, no CISA KEV listing, and a low EPSS score of 0.2% (16th percentile), indicating no known exploitation.

What to do: Apply Microsoft's security update for the affected Windows versions as soon as it is available via Windows Update, prioritizing multi-user systems such as RDS hosts, shared workstations, and servers that permit logon by untrusted accounts. Because exploitation requires local low-privileged access, restricting interactive logon rights on sensitive systems reduces exposure. Check Microsoft's advisory for the specific list of affected versions, which is not included in this dataset.

Affected
Microsoft Windows (NTFS component)
Estimated exposure
mass≈1 billion+ Windows installations (NTFS is the default filesystem on Windows) — The estimate is based on Microsoft's publicly stated installed base of over a billion active Windows devices, all of which ship with NTFS as the default filesystem, though practical exposure is limited to systems where untrusted local…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Buffer over-read in Windows NTFS allows an authorized attacker to execute code locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-126
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.