ZeroHour

CVE-2026-69340

mass

Heap Buffer Overflow in Windows NTFS Enables Network Privilege Escalation

CVSS 3.1
7.1 high
EPSS
<1%p43
Published
()
Modified
AI analysis

CVE-2026-69340 is a heap-based buffer overflow (heap out-of-bounds read) in the Windows NTFS component. It is triggered when an authorized, low-privileged attacker delivers a maliciously crafted NTFS structure over the network; exploitation involves high attack complexity and requires some user interaction. A successful exploit allows the attacker to elevate privileges, with high impact on the confidentiality, integrity, and availability of the target system. All Windows deployments using NTFS are potentially affected, though the provided data does not specify affected Windows versions or builds. As of this analysis there is no known exploitation, no public proof-of-concept, the CVE is not in CISA's KEV, and EPSS estimates only a 0.5% probability of exploitation in the next 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69340 as soon as it is available, checking Microsoft's advisory for the exact affected builds since version ranges were not provided in this data. Until patched, reduce exposure by limiting remote/low-privileged access to hosts that process untrusted NTFS-mounted volumes and reviewing which systems expose NTFS-parsing attack surface over the network. Monitor for public PoCs or KEV listing, as either would warrant prioritized patching.

Affected
Microsoft Windows (NTFS component)
Estimated exposure
mass>1 billion Windows installations (NTFS is the default filesystem across Windows deployments) — Windows runs on well over a billion active devices worldwide and NTFS is its default filesystem, so the candidate population is effectively the entire Windows installed base; however, actual exploit exposure is narrower because the attack…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-122, CWE-125
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.