Impact
A heap‑based buffer overflow in Windows NTFS allows an unauthorized local attacker to execute code. The flaw originates from improper handling of file system data structures during normal file operations, causing an overflow of a heap buffer in the NTFS driver. Successful exploitation can give the attacker the privileges of the caller, potentially reaching SYSTEM level if executed under a high‑privileged context. This vulnerability is identified as CWE‑122 and can severely compromise confidentiality, integrity, and availability.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2, as well as Windows 11 versions 23H2, 24H2, 25H2, and 26H1, are affected. The same heap overflow exists in Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025—including full‑blown and Server‑Core installations—according to the Microsoft Security Update Guide for CVE‑2026‑69479.
Risk and Exploitability
The CVSS score of 8.4 reflects high severity, and the lack of an EPSS value indicates no recent exploitation data. The attack vector is local; any local user who can place a crafted file on a volume processed by the victim system can trigger the overflow. While the vulnerability is not listed in CISA’s KEV catalog and there are no known public exploits, the ability to execute code locally with elevated rights makes it a top priority for patching.
OpenCVE Enrichment