CVE-2026-77503
massOut-of-bounds Read in Windows NTFS Enables Local Privilege Escalation
CVE-2026-77503 is an out-of-bounds read (CWE-125) in the Windows NTFS component that Microsoft rates High (CVSS 3.1: 7.8) for local privilege escalation. An attacker who already has low-privileged local access (no user interaction required) can trigger the flaw via the NTFS filesystem component, causing memory to be read beyond allocated bounds and gaining elevated, administrator/SYSTEM-level privileges with high impact on confidentiality, integrity, and availability of the local machine. Affected systems include Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server 2012, 2016, 2019, and 2022, which together span essentially the entire mainstream Windows client and server fleet. There is currently no known exploitation: the flaw is not in CISA KEV, no public proof-of-concept exists, and EPSS is 0.3% (19th percentile), indicating low near-term exploitation probability.
What to do: Apply Microsoft's security update for the affected Windows versions via Windows Update or the Microsoft Update Catalog, prioritizing shared and multi-user systems (RDS hosts, VDI, jump boxes, kiosks) where untrusted low-privileged local users are common. No workaround is published; as an interim measure, restrict local sign-in rights to trusted users on multi-user systems and watch for emerging PoCs or KEV inclusion given the low current EPSS.
| Microsoft Windows 10 | 1607, 1809, 21H2, 22H2 |
| Microsoft Windows 11 | 23H2, 24H2, 25H2, 26H1 |
| Microsoft Windows Server | 2012, 2016, 2019, 2022 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.