CVE-2026-69875
massHeap Buffer Overflow in Windows NTFS Enables Network-Based Privilege Escalation
CVE-2026-69875 is a heap-based buffer overflow (CWE-122, with an associated out-of-bounds read, CWE-125) in the Windows NTFS component, rated 8.0 (High) on CVSS 3.1. Per Microsoft's description, an authorized (low-privileged) attacker can trigger the flaw over a network; the CVSS vector also indicates some user interaction is required, which is consistent with the vulnerable NTFS code processing attacker-influenced filesystem data. A successful exploit elevates the attacker's privileges, with high impact on confidentiality, integrity, and availability on the compromised system. Any organization running affected Windows releases is exposed, though the source data does not specify which Windows version ranges are affected. There is no evidence of active exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.8% probability of exploitation within 30 days (53rd percentile).
What to do: Track Microsoft's advisory for the exact affected Windows versions and apply the security update via Windows Update or the Microsoft Update Catalog as soon as it is available. In the interim, enforce least privilege on Windows hosts and restrict which users can attach or mount NTFS volumes or disk images, since exploitation requires valid low-privileged credentials plus user interaction. Given the moderate EPSS baseline, monitor for the emergence of a public PoC, KEV listing, or in-the-wild reports and reprioritize patching accordingly.
| Microsoft Windows (NTFS component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
- Vendors
- microsoft
- Products
- windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122, CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.