CVE-2026-69463
massHeap-Based Buffer Overflow in Windows NTFS Enables Unauthenticated Remote Code Execution
CVE-2026-69463 is a heap-based buffer overflow (CWE-122) in the Windows NTFS component that Microsoft rates critical (CVSS 9.8). The flaw can be triggered remotely by an unauthorized, unauthenticated attacker with no user interaction, which suggests attacker-controlled data reaches the NTFS parsing code over the network. Successful exploitation would allow the attacker to execute arbitrary code in the context of the affected service, with potential for full confidentiality, integrity, and availability impact. Any organization running Windows systems that use NTFS is potentially in scope, though Microsoft's advisory governs the exact affected versions, which are not detailed in the available data. There is currently no known in-the-wild exploitation and no public proof-of-concept; EPSS places 30-day exploitation probability at roughly 0.9%.
What to do: Monitor Microsoft's advisory and apply the vendor patch as soon as it is released, prioritizing internet-facing Windows servers and any systems exposing file-sharing or NTFS-parsing services. Until patched, restrict unauthenticated network access to affected Windows hosts where feasible. Because the affected version range is not yet specified in available data, inventory Windows builds against Microsoft's published affected-products list rather than assuming broad or narrow applicability.
| Microsoft Windows (NTFS component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.