CVE-2026-69505: Windows NTFS Elevation of Privilege Vulnerability
Published Sep 8, 2026
·Updated
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network.
Other sources
Windows NTFS Elevation of Privilege Vulnerability
— Microsoft
Affected Software
1 affected component
Microsoft Windows NTFS
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
CVE Published
via MITRE·05:11 PM
Data Sourced
via MITRE·05:11 PM
DescriptionSeverity
Data Sourced
via NVD·06:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this vulnerability?
The attacker must already be authorized, requiring low-level privileges before exploitation. Exploitation can be performed over a network and requires user interaction.
2
What is the potential impact if exploitation succeeds?
Successful exploitation allows elevation of privilege. The supplied severity vector indicates high potential impact to confidentiality, integrity, and availability.
3
Is this issue remotely exploitable?
Yes. The attack vector is network-based, so the vulnerable NTFS functionality may be reached over a network by an authorized attacker.