CVE-2026-56182: Windows NTFS Elevation of Privilege Vulnerability
Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.
Other sources
Windows NTFS Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Systems running the listed Microsoft Windows 10, Windows 11, or supported Windows Server versions are in scope. Exploitation is local, so the attacker must be able to execute code or otherwise operate on the affected host.
What level of access does an attacker need?
The attacker must already be authorized on the vulnerable system with low privileges. No user interaction is required, and successful exploitation can elevate the attacker’s privileges locally.
What is the potential impact of successful exploitation?
Successful exploitation can result in high-impact compromise of confidentiality, integrity, and availability on the affected system. The vulnerability affects the Windows NTFS component through an integer overflow or wraparound condition.
What should teams do if affected systems cannot be patched immediately?
The provided data identifies a patch as available. No alternative mitigation or workaround is specified, so prioritizing installation of the available patch is the documented remediation.