ZeroHour

CVE-2026-69312

mass

Out-of-Bounds Read in Windows NTFS Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69312 is an out-of-bounds read (CWE-125) in the Windows NTFS file system component, rated 7.8 (High) with a local attack vector and only low privileges required. An authorized local user can trigger the flaw through file-system operations that cause NTFS to read past the bounds of an allocated buffer. Successful exploitation lets the attacker elevate privileges on the local machine, with high impact on confidentiality, integrity, and availability per the CVSS scoring. Any Windows system running NTFS is potentially affected, though the available data does not specify which Windows versions or builds are vulnerable. Exploitation status is currently quiet: no public proof-of-concept, not listed in CISA KEV, and a low 0.3% EPSS probability of exploitation within 30 days.

What to do: Apply the Microsoft security update that addresses CVE-2026-69312 as soon as it is released, checking Microsoft's advisory for the exact affected version ranges since they are not listed here. Because this is a local privilege escalation requiring an authorized low-privileged user, prioritize multi-user systems such as RDS/session hosts, shared servers, and workstations where untrusted users can run code. No public exploit or in-the-wild exploitation is known, and no workaround is documented in the available data.

Affected
Microsoft Windows (NTFS)
Estimated exposure
mass≈1.4 billion+ Windows devices (NTFS is the default file system on Windows installations) — NTFS ships by default on essentially all Windows installations and Microsoft has reported over 1.4 billion monthly active Windows devices, so every unpatched Windows host is potentially exposed to this local privilege escalation.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.