CVE-2026-69638
massHeap-Based Buffer Overflow in Windows NTFS Enables Local Code Execution
CVE-2026-69638 is a heap-based buffer overflow (CWE-122) in the NTFS filesystem component of Microsoft Windows, rated 8.4 (High) with a local attack vector, low attack complexity, no required privileges, and no user interaction. A local, unprivileged attacker can trigger the overflow via filesystem operations handled by the NTFS driver; because the NTFS driver operates in kernel mode, successful exploitation likely yields system-level code execution, effectively an elevation of privilege, with high impact on confidentiality, integrity, and availability. Any Windows system running the affected NTFS code is potentially affected, though exploitation requires local access rather than network reachability. Exact affected Windows version ranges are not specified in the available data, so defenders should confirm coverage against Microsoft's advisory. Exploitation status: no public proof-of-concept is known, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Patch via Microsoft's security update for CVE-2026-69638 as soon as it is published; consult the Microsoft Security Response Center advisory and the Windows Update catalog to confirm which builds are covered, since exact version ranges are not enumerated here. In the interim, prioritize hosts that permit untrusted local logon or multi-user/RDP access, and restrict local execution rights to trusted users. Monitor Microsoft's advisory for any updates on affected editions and exploitation activity.
| Microsoft Windows (NTFS filesystem component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.