Abstract illustration of connected devices separated by a protected security boundary.
Microsoft has released fixes for CVE-2026-69265, Windows NTFS Elevation of Privilege Vulnerability, an Important-severity flaw in the Windows NTFS file system. The vulnerability is an out-of-bounds read, tracked as CWE-125, that could allow an authorized attacker to elevate privileges locally.

Microsoft’s advisory states: “Windows NTFS Elevation of Privilege Vulnerability: Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.” The company further says that an attacker who successfully exploited the vulnerability could gain SYSTEM privileges—the highest local privilege level in Windows. In short: this is not a remote break-in by itself, but it could become a highly valuable second step after an attacker has obtained access to a machine.

CVE-2026-69265 at a glance​

  • CVE: CVE-2026-69265
  • Title: Windows NTFS Elevation of Privilege Vulnerability
  • Severity: Important
  • CWE: CWE-125
  • CVSS base score: 7.8
  • CVSS temporal score: 6.8
  • CVSS vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
  • Description: Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
  • Publicly disclosed: No
  • Exploited: No
  • Customer action required: Yes
  • Exploitation assessment: Exploitation Unlikely

The CVSS vector describes a locally accessible flaw with low attack complexity and low privileges required. No user interaction is required. Successful exploitation can affect confidentiality, integrity, and availability, which helps explain why an elevation-of-privilege issue receives a 7.8 base score even though the attack is local.

Why NTFS vulnerabilities deserve prompt attention​

NTFS is Windows’ principal file system and sits beneath a vast amount of everyday activity: opening documents, installing software, updating applications, handling permissions, and managing storage. A flaw in that layer is consequential because a compromised standard user account—or malware already running in that user’s context—may attempt to turn modest access into SYSTEM-level control.

Microsoft’s “Exploitation Unlikely” assessment is welcome context, but it is not a reason to leave endpoints unpatched. Local privilege escalation bugs are often combined with other weaknesses in real-world intrusion chains. The practical takeaway for administrators is pleasantly unglamorous: deploy the applicable cumulative update, confirm the resulting OS build, and treat that verification as the finish line rather than the download button.

Affected products and fixed builds​

The following product versions are affected and have corresponding Microsoft updates and fixed builds.

Windows 10​

Affected productUpdateFixed build
Windows 10 Version 1607 for 32-bit Systems (x86)KB512309910.0.14393.9512
Windows 10 Version 1607 for x64-based SystemsKB512309910.0.14393.9512
Windows 10 Version 1809 for 32-bit Systems (x86)KB512287610.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsKB512287610.0.17763.9245
Windows 10 Version 21H2 for 32-bit Systems (x86)KB512287810.0.19044.7725
Windows 10 Version 21H2 for ARM64-based SystemsKB512287810.0.19044.7725
Windows 10 Version 21H2 for x64-based SystemsKB512287810.0.19044.7725
Windows 10 Version 22H2 for 32-bit Systems (x86)KB512287810.0.19045.7725
Windows 10 Version 22H2 for ARM64-based SystemsKB512287810.0.19045.7725
Windows 10 Version 22H2 for x64-based SystemsKB512287810.0.19045.7725

Windows 11​

Affected productUpdateFixed build
Windows 11 Version 23H2 for ARM64-based SystemsKB512288010.0.22631.7582
Windows 11 Version 23H2 for x64-based SystemsKB512288010.0.22631.7582
Windows 11 Version 24H2 for ARM64-based SystemsKB512400810.0.26100.9445
Windows 11 Version 24H2 for x64-based SystemsKB512400810.0.26100.9445
Windows 11 Version 25H2 for ARM64-based SystemsKB512400810.0.26200.9445
Windows 11 Version 25H2 for x64-based SystemsKB512400810.0.26200.9445
Windows 11 Version 26H1 for ARM64-based SystemsKB512401210.0.28000.2954
Windows 11 version 26H1 for x64-based SystemsKB512401210.0.28000.2954

Windows Server​

Affected productUpdateFixed build
Windows Server 2012 (Server Core installation) (x64)KB51230656.2.9200.26349
Windows Server 2012 (x64)KB51230656.2.9200.26349
Windows Server 2012 R2 (Server Core installation) (x64)KB51230666.3.9600.23398
Windows Server 2012 R2 (x64)KB51230666.3.9600.23398
Windows Server 2016 (Server Core installation) (x64)KB512309910.0.14393.9512
Windows Server 2016 (x64)KB512309910.0.14393.9512
Windows Server 2019 (Server Core installation) (x64)KB512287610.0.17763.9245
Windows Server 2019 (x64)KB512287610.0.17763.9245
Windows Server 2022 (Server Core installation) (x64)KB512288210.0.20348.5622
Windows Server 2022 (x64)KB512288210.0.20348.5622
Windows Server 2025 (Server Core installation) (x64)KB512287110.0.26100.33438
Windows Server 2025 (x64)KB512287110.0.26100.33438

Remediation​

Apply the update that corresponds to the installed Windows release and processor architecture:

  • For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows 10 Version 1607 for x64-based Systems, install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows 10 Version 1809 for x64-based Systems, install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows 10 Version 21H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19044.7725.
  • For Windows 10 Version 21H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.
  • For Windows 10 Version 21H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.
  • For Windows 10 Version 22H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19045.7725.
  • For Windows 10 Version 22H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.
  • For Windows 10 Version 22H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.
  • For Windows 11 Version 23H2 for ARM64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
  • For Windows 11 Version 23H2 for x64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
  • For Windows 11 Version 24H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
  • For Windows 11 Version 24H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
  • For Windows 11 Version 25H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
  • For Windows 11 Version 25H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
  • For Windows 11 Version 26H1 for ARM64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.
  • For Windows 11 version 26H1 for x64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.
  • For Windows Server 2012 (Server Core installation) (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
  • For Windows Server 2012 (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
  • For Windows Server 2012 R2 (Server Core installation) (x64), install KB5123066 to reach fixed build 6.3.9600.23398.
  • For Windows Server 2012 R2 (x64), install KB5123066 to reach fixed build 6.3.9600.23398.
  • For Windows Server 2016 (Server Core installation) (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows Server 2016 (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows Server 2019 (Server Core installation) (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows Server 2019 (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
  • For Windows Server 2022 (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
  • For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438.
  • For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438.

For IT teams, the operational priority is straightforward: identify endpoints and servers on the listed releases, deploy the matching cumulative update through the organization’s normal update-management process, restart where required, and verify that systems report the specified fixed build. That closes the NTFS privilege-escalation path addressed by CVE-2026-69265.

 

References

  1. Official MSRC or vendor evidence api.msrc.microsoft.com
  2. Official MSRC or vendor evidence msrc.microsoft.com
  3. Official MSRC or vendor evidence api.msrc.microsoft.com