CVE-2026-69479
massHeap Buffer Overflow in Microsoft Windows NTFS Enables Local Code Execution
CVE-2026-69479 is a heap-based buffer overflow (CWE-122) in the NTFS component of Microsoft Windows, assigned by Microsoft as the CNA. The CVSS vector (AV:L/AC:L/PR:N/UI:N) indicates the flaw can be triggered locally with no privileges required and no user interaction, meaning unprivileged code already running on a machine or a local user could provoke the overflow. Successful exploitation lets an unauthorized attacker execute code on the affected host, and the high confidentiality, integrity, and availability impact ratings indicate potentially significant system-level compromise; defenders typically treat this class of NTFS flaw as a privilege-escalation risk that can be chained with other bugs. Because NTFS is the default filesystem on Windows, effectively all supported Windows client and server installations are in scope. The flaw is not yet known to be exploited: there is no public proof-of-concept, it is not in CISA's KEV, and EPSS estimates only a 0.3% chance of exploitation within 30 days (28th percentile).
What to do: Apply the Windows security update referenced in Microsoft's advisory for your Windows version once released, confirming coverage through Windows Update, WSUS, or Intune. No practical workaround exists for a filesystem-driver overflow, so prioritize internet-facing and multi-user hosts where an NTFS flaw could be chained with remote code execution for full compromise. Check Microsoft's advisory for the exact affected builds and KB article rather than assuming version ranges.
| Microsoft Windows (NTFS component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.