CVE-2026-69312
massOut-of-Bounds Read in Windows NTFS Enables Local Privilege Escalation
CVE-2026-69312 is an out-of-bounds read (CWE-125) in the Windows NTFS file system component, rated 7.8 (High) with a local attack vector and only low privileges required. An authorized local user can trigger the flaw through file-system operations that cause NTFS to read past the bounds of an allocated buffer. Successful exploitation lets the attacker elevate privileges on the local machine, with high impact on confidentiality, integrity, and availability per the CVSS scoring. Any Windows system running NTFS is potentially affected, though the available data does not specify which Windows versions or builds are vulnerable. Exploitation status is currently quiet: no public proof-of-concept, not listed in CISA KEV, and a low 0.3% EPSS probability of exploitation within 30 days.
What to do: Apply the Microsoft security update that addresses CVE-2026-69312 as soon as it is released, checking Microsoft's advisory for the exact affected version ranges since they are not listed here. Because this is a local privilege escalation requiring an authorized low-privileged user, prioritize multi-user systems such as RDS/session hosts, shared servers, and workstations where untrusted users can run code. No public exploit or in-the-wild exploitation is known, and no workaround is documented in the available data.
| Microsoft Windows (NTFS) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.