Microsoft’s advisory states: “Windows NTFS Elevation of Privilege Vulnerability: Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.” The company further says that an attacker who successfully exploited the vulnerability could gain SYSTEM privileges—the highest local privilege level in Windows. In short: this is not a remote break-in by itself, but it could become a highly valuable second step after an attacker has obtained access to a machine.
CVE-2026-69265 at a glance
- CVE: CVE-2026-69265
- Title: Windows NTFS Elevation of Privilege Vulnerability
- Severity: Important
- CWE: CWE-125
- CVSS base score: 7.8
- CVSS temporal score: 6.8
- CVSS vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C - Description: Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
- Publicly disclosed: No
- Exploited: No
- Customer action required: Yes
- Exploitation assessment: Exploitation Unlikely
The CVSS vector describes a locally accessible flaw with low attack complexity and low privileges required. No user interaction is required. Successful exploitation can affect confidentiality, integrity, and availability, which helps explain why an elevation-of-privilege issue receives a 7.8 base score even though the attack is local.
Why NTFS vulnerabilities deserve prompt attention
NTFS is Windows’ principal file system and sits beneath a vast amount of everyday activity: opening documents, installing software, updating applications, handling permissions, and managing storage. A flaw in that layer is consequential because a compromised standard user account—or malware already running in that user’s context—may attempt to turn modest access into SYSTEM-level control.
Microsoft’s “Exploitation Unlikely” assessment is welcome context, but it is not a reason to leave endpoints unpatched. Local privilege escalation bugs are often combined with other weaknesses in real-world intrusion chains. The practical takeaway for administrators is pleasantly unglamorous: deploy the applicable cumulative update, confirm the resulting OS build, and treat that verification as the finish line rather than the download button.
Affected products and fixed builds
The following product versions are affected and have corresponding Microsoft updates and fixed builds.
Windows 10
| Affected product | Update | Fixed build |
|---|---|---|
| Windows 10 Version 1607 for 32-bit Systems (x86) | KB5123099 | 10.0.14393.9512 |
| Windows 10 Version 1607 for x64-based Systems | KB5123099 | 10.0.14393.9512 |
| Windows 10 Version 1809 for 32-bit Systems (x86) | KB5122876 | 10.0.17763.9245 |
| Windows 10 Version 1809 for x64-based Systems | KB5122876 | 10.0.17763.9245 |
| Windows 10 Version 21H2 for 32-bit Systems (x86) | KB5122878 | 10.0.19044.7725 |
| Windows 10 Version 21H2 for ARM64-based Systems | KB5122878 | 10.0.19044.7725 |
| Windows 10 Version 21H2 for x64-based Systems | KB5122878 | 10.0.19044.7725 |
| Windows 10 Version 22H2 for 32-bit Systems (x86) | KB5122878 | 10.0.19045.7725 |
| Windows 10 Version 22H2 for ARM64-based Systems | KB5122878 | 10.0.19045.7725 |
| Windows 10 Version 22H2 for x64-based Systems | KB5122878 | 10.0.19045.7725 |
Windows 11
| Affected product | Update | Fixed build |
|---|---|---|
| Windows 11 Version 23H2 for ARM64-based Systems | KB5122880 | 10.0.22631.7582 |
| Windows 11 Version 23H2 for x64-based Systems | KB5122880 | 10.0.22631.7582 |
| Windows 11 Version 24H2 for ARM64-based Systems | KB5124008 | 10.0.26100.9445 |
| Windows 11 Version 24H2 for x64-based Systems | KB5124008 | 10.0.26100.9445 |
| Windows 11 Version 25H2 for ARM64-based Systems | KB5124008 | 10.0.26200.9445 |
| Windows 11 Version 25H2 for x64-based Systems | KB5124008 | 10.0.26200.9445 |
| Windows 11 Version 26H1 for ARM64-based Systems | KB5124012 | 10.0.28000.2954 |
| Windows 11 version 26H1 for x64-based Systems | KB5124012 | 10.0.28000.2954 |
Windows Server
| Affected product | Update | Fixed build |
|---|---|---|
| Windows Server 2012 (Server Core installation) (x64) | KB5123065 | 6.2.9200.26349 |
| Windows Server 2012 (x64) | KB5123065 | 6.2.9200.26349 |
| Windows Server 2012 R2 (Server Core installation) (x64) | KB5123066 | 6.3.9600.23398 |
| Windows Server 2012 R2 (x64) | KB5123066 | 6.3.9600.23398 |
| Windows Server 2016 (Server Core installation) (x64) | KB5123099 | 10.0.14393.9512 |
| Windows Server 2016 (x64) | KB5123099 | 10.0.14393.9512 |
| Windows Server 2019 (Server Core installation) (x64) | KB5122876 | 10.0.17763.9245 |
| Windows Server 2019 (x64) | KB5122876 | 10.0.17763.9245 |
| Windows Server 2022 (Server Core installation) (x64) | KB5122882 | 10.0.20348.5622 |
| Windows Server 2022 (x64) | KB5122882 | 10.0.20348.5622 |
| Windows Server 2025 (Server Core installation) (x64) | KB5122871 | 10.0.26100.33438 |
| Windows Server 2025 (x64) | KB5122871 | 10.0.26100.33438 |
Remediation
Apply the update that corresponds to the installed Windows release and processor architecture:
- For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5123099 to reach fixed build 10.0.14393.9512.
- For Windows 10 Version 1607 for x64-based Systems, install KB5123099 to reach fixed build 10.0.14393.9512.
- For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5122876 to reach fixed build 10.0.17763.9245.
- For Windows 10 Version 1809 for x64-based Systems, install KB5122876 to reach fixed build 10.0.17763.9245.
- For Windows 10 Version 21H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19044.7725.
- For Windows 10 Version 21H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.
- For Windows 10 Version 21H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.
- For Windows 10 Version 22H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19045.7725.
- For Windows 10 Version 22H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.
- For Windows 10 Version 22H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.
- For Windows 11 Version 23H2 for ARM64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
- For Windows 11 Version 23H2 for x64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
- For Windows 11 Version 24H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
- For Windows 11 Version 24H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
- For Windows 11 Version 25H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
- For Windows 11 Version 25H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
- For Windows 11 Version 26H1 for ARM64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.
- For Windows 11 version 26H1 for x64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.
- For Windows Server 2012 (Server Core installation) (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
- For Windows Server 2012 (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
- For Windows Server 2012 R2 (Server Core installation) (x64), install KB5123066 to reach fixed build 6.3.9600.23398.
- For Windows Server 2012 R2 (x64), install KB5123066 to reach fixed build 6.3.9600.23398.
- For Windows Server 2016 (Server Core installation) (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
- For Windows Server 2016 (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
- For Windows Server 2019 (Server Core installation) (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
- For Windows Server 2019 (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
- For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
- For Windows Server 2022 (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
- For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438.
- For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438.
For IT teams, the operational priority is straightforward: identify endpoints and servers on the listed releases, deploy the matching cumulative update through the organization’s normal update-management process, restart where required, and verify that systems report the specified fixed build. That closes the NTFS privilege-escalation path addressed by CVE-2026-69265.
References
- Official MSRC or vendor evidence api.msrc.microsoft.com
- Official MSRC or vendor evidence msrc.microsoft.com
- Official MSRC or vendor evidence api.msrc.microsoft.com