CVE-2026-69709
massHeap-Based Buffer Overflow in Windows NTFS Enables Local Code Execution
CVE-2026-69709 is a heap-based buffer overflow (CWE-122) in the Windows NTFS filesystem component, reported and coordinated by Microsoft and rated High (CVSS 3.1: 7.8). It is triggered locally by an already-authorized low-privileged attacker, with no user interaction required, by getting malformed data processed by the NTFS component. A successful exploit yields local code execution with high impact on the confidentiality, integrity, and availability of the host. Because NTFS is the default filesystem on effectively every Windows client and server, the potentially affected population spans the entire Windows installed base, though exploitation requires an attacker (or malware) to already hold local access. There is no known public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Install the corresponding Microsoft security update for this CVE on all Windows endpoints and servers, prioritizing multi-user hosts (terminal/RDS servers, shared workstations, kiosks) and machines where untrusted users can execute code, since exploitation requires local privileges. No workaround is documented in the available data, so patching is the primary mitigation; with no public PoC, no KEV entry, and EPSS at 0.3%, standard patch cycles are defensible for lower-risk estates, but re-check EPSS/KEV for escalation.
| Microsoft Windows (NTFS filesystem component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.