ZeroHour

CVE-2026-77503

mass

Out-of-bounds Read in Windows NTFS Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p15
Published
()
Modified
AI analysis

CVE-2026-77503 is an out-of-bounds read (CWE-125) in the Windows NTFS component that Microsoft rates High (CVSS 3.1: 7.8) for local privilege escalation. An attacker who already has low-privileged local access (no user interaction required) can trigger the flaw via the NTFS filesystem component, causing memory to be read beyond allocated bounds and gaining elevated, administrator/SYSTEM-level privileges with high impact on confidentiality, integrity, and availability of the local machine. Affected systems include Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server 2012, 2016, 2019, and 2022, which together span essentially the entire mainstream Windows client and server fleet. There is currently no known exploitation: the flaw is not in CISA KEV, no public proof-of-concept exists, and EPSS is 0.3% (19th percentile), indicating low near-term exploitation probability.

What to do: Apply Microsoft's security update for the affected Windows versions via Windows Update or the Microsoft Update Catalog, prioritizing shared and multi-user systems (RDS hosts, VDI, jump boxes, kiosks) where untrusted low-privileged local users are common. No workaround is published; as an interim measure, restrict local sign-in rights to trusted users on multi-user systems and watch for emerging PoCs or KEV inclusion given the low current EPSS.

Affected
Microsoft Windows 101607, 1809, 21H2, 22H2
Microsoft Windows 1123H2, 24H2, 25H2, 26H1
Microsoft Windows Server2012, 2016, 2019, 2022
Estimated exposure
mass≈1 billion+ Windows 10/11 endpoints plus millions of Windows Server instances (order of magnitude, based on installed base) — Every mainstream Windows 10 and Windows 11 branch and four widely deployed Windows Server releases are affected, so essentially the entire Windows installed base (roughly 1.4 billion Windows devices, with Windows Server pervasive in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.