CVE-2026-69265
massOut-of-Bounds Read in Windows NTFS Enables Local Privilege Escalation
CVE-2026-69265 is an out-of-bounds read (CWE-125) in the Windows NTFS component, assigned by Microsoft with a CVSS 3.1 score of 7.8 (high). An authorized attacker with low-level local access (a standard authenticated user) can trigger the flaw through NTFS operations, causing the affected component to read beyond allocated memory boundaries. Successful exploitation elevates the attacker's privileges locally, with the CVSS vector indicating high impact on confidentiality, integrity, and availability, consistent with gaining higher-privilege access on the host. Any Windows system running NTFS is in scope per the published description, and no specific version ranges were provided in the available data. As of this analysis, there are no known public proofs of concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days (16th percentile), indicating no known exploitation to date.
What to do: Patch via Windows Update as soon as Microsoft releases the security update addressing CVE-2026-69265, and verify the updated NTFS driver is applied on your hosts. Until then, limit local logon and standard-user access on high-value systems to trusted accounts, since exploitation requires an authenticated local user. Given no known PoC or in-the-wild exploitation and low EPSS, routine patch-cycle prioritization is reasonable, but prioritize multi-user and shared-access Windows hosts.
| Microsoft Windows (NTFS component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.