CVE-2026-68841: Windows NTFS Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
Other sources
Windows NTFS Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must already be authorized to access the affected Windows system and must be able to execute an exploit locally. It is not described as remotely exploitable and does not require user interaction.
What is the likely impact of successful exploitation?
Successful exploitation can elevate an authorized local attacker’s privileges. The supplied severity vector indicates high impact to confidentiality, integrity, and availability.
Which systems should be assessed?
Assess Microsoft Windows 10 and Windows 11, plus Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025. The provided data does not identify affected build numbers, update levels, or configuration-specific exclusions.