ZeroHour

CVE-2026-69332

mass

Out-of-Bounds Read in Windows NTFS Allows Network Elevation of Privilege

CVSS 3.1
8.0 high
EPSS
<1%p51
Published
()
Modified
AI analysis

CVE-2026-69332 is an out-of-bounds read (CWE-125) flaw in the Windows NTFS component that can be triggered over the network by an attacker who already holds low-privileged, authorized access, with user interaction required. Successful exploitation allows the attacker to elevate privileges, with the CVSS vector indicating high impact on confidentiality, integrity, and availability. Any Windows deployment using NTFS is in scope, which effectively means virtually all Windows environments. As of now there is no known exploitation in the wild, no public proof of concept, and the EPSS score of 0.7% suggests low near-term exploitation likelihood.

What to do: Track Microsoft's advisory for CVE-2026-69332 and apply the corresponding Windows security update via Windows Update or your patch management process as soon as it is released, prioritizing hosts that expose interactive sessions to untrusted or low-privileged network users. Until patched, limit unprivileged network access and treat user-driven interaction with untrusted content as the likely trigger path; check EDR and exploit-protection telemetry for anomalous NTFS driver activity.

Affected
Microsoft Windows (NTFS component)
Estimated exposure
masshundreds of millions of Windows systems (NTFS is the default filesystem on effectively all Windows installations) — NTFS ships as the default filesystem across the entire Windows installed base, commonly estimated in the hundreds of millions to over a billion devices, so exposure is assumed at mass scale even though only configurations reachable by…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.