CVE-2026-69505
massOut-of-bounds read in Windows NTFS enables network privilege escalation
CVE-2026-69505 is an out-of-bounds read (CWE-125) in the Windows NTFS component, in which the driver reads past the end of an allocated buffer when handling certain filesystem data. Per the CVSS vector, an attacker needs network reach to the target, valid low-privileged credentials, and some user interaction to trigger the flaw. Successful exploitation yields elevation of privilege with high impact on confidentiality, integrity, and availability on the compromised system. Any Windows system using NTFS is in scope, making the potential population effectively the entire Windows installed base. Exploitation status: no public proof-of-concept, not listed in CISA KEV, and EPSS puts current exploitation probability at about 0.8% over the next 30 days (53rd percentile).
What to do: Patch as soon as Microsoft releases the fix, prioritizing internet-reachable Windows servers and multi-user systems, since the flaw is network-vector privilege escalation requiring only low-privileged access. Until patched, limit low-privileged users' ability to mount or interact with untrusted NTFS volumes/images and watch Microsoft's MSRC advisory for the definitive list of affected builds. As no public PoC or in-the-wild exploitation is known, this can be scheduled within normal patch cycles but should not be deferred past the next Patch Tuesday.
| Microsoft Windows (NTFS filesystem/driver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.