CVE-2026-69532
massOut-of-bounds Read in Windows NTFS Enables Local Privilege Escalation
CVE-2026-69532 is an out-of-bounds read (CWE-125) in the Windows NTFS file system component, rated 7.8 (High) with a CVSS vector indicating a local attack that requires only low privileges and no user interaction. A locally authenticated, low-privileged attacker can trigger the flaw through interaction with the NTFS file system, causing the component to read beyond the intended buffer. Successful exploitation allows the attacker to elevate privileges on the local machine, with high impact on confidentiality, integrity, and availability, effectively yielding elevated system access. Any Windows system using NTFS is potentially affected, although the provided data does not specify which Windows version ranges are impacted. No public proof of concept is known, the flaw is not in CISA's KEV, and EPSS assigns a 0.3% probability of exploitation within 30 days (25th percentile), indicating low current exploitation risk.
What to do: Monitor Microsoft's advisory for CVE-2026-69532 and apply the corresponding Windows security update as soon as it is published, prioritizing multi-user hosts such as terminal servers and shared workstations where untrusted accounts can log on. Since the affected version ranges are not listed in the available data, verify applicability against Microsoft's bulletin; until patched, restrict interactive/local logon on sensitive systems to trusted users and watch for the emergence of public PoCs.
| Microsoft Windows NTFS | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.