CVE-2026-68875
massBuffer over-read in Windows NTFS enables local code execution
CVE-2026-68875 is a buffer over-read (CWE-126) in the NTFS filesystem component of Microsoft Windows. Per the CVSS vector (AV:L/AC:L/PR:L/UI:N), an authorized attacker with low privileges on the system can trigger the flaw locally, with no user interaction required. Successful exploitation yields local code execution with high impact to confidentiality, integrity, and availability; because NTFS is implemented in kernel mode, this plausibly permits full system compromise, though Microsoft's description does not explicitly label it privilege escalation. Practically, risk is concentrated on Windows systems where an untrusted or lower-privileged user can run code. There is currently no public proof-of-concept, no CISA KEV listing, and a low EPSS score of 0.2% (16th percentile), indicating no known exploitation.
What to do: Apply Microsoft's security update for the affected Windows versions as soon as it is available via Windows Update, prioritizing multi-user systems such as RDS hosts, shared workstations, and servers that permit logon by untrusted accounts. Because exploitation requires local low-privileged access, restricting interactive logon rights on sensitive systems reduces exposure. Check Microsoft's advisory for the specific list of affected versions, which is not included in this dataset.
| Microsoft Windows (NTFS component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Buffer over-read in Windows NTFS allows an authorized attacker to execute code locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-126
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.