Impact
Stack‑based buffer overflow in the Windows NTFS filesystem enables an attacker with authorized access to a network share to gain higher privileges on the host. The flaw exploits poorly bounded data on the stack, allowing arbitrary code execution that can bypass existing security restrictions. Successful exploitation would increase an attacker’s privileges to that of the user executing the vulnerable code, potentially giving them system‑level access and allowing further compromise. The weakness stems from CWE‑121, a classic stack buffer overflow flaw.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Windows Server 2012, Server 2012 R2, Server 2016, Server 2019, Server 2022, and Server 2025, including both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 8.0 indicates a high severity risk. EPSS information is not available, so the likelihood of exploitation is unknown, though the vulnerability is active in many widely deployed Windows releases. The flaw is listed in the Microsoft security advisory (CVE‑2026‑68838) but is not included in the CISA KEV catalog. Attack is inferred to be network‑based, requiring an attacker to have authorized access to a file share that is vulnerable, but detailed prerequisites are not provided in the description.
OpenCVE Enrichment