Abstract illustration of connected devices separated by a protected security boundary.
Microsoft has released security updates for CVE-2026-69340: Windows NTFS Elevation of Privilege Vulnerability, an Important-rated flaw in the Windows NTFS file system. The issue is a heap-based buffer overflow that allows an authorized attacker to elevate privileges over a network. In a successful attack, Microsoft says the attacker could gain SYSTEM privileges—the highest local privilege level on a Windows machine.

That end result is serious, even if the exploit’s path is not a walk in the park. Microsoft’s assessment is Exploitation Less Likely, and the advisory says successful exploitation requires high attack complexity and a deep understanding of the target system, its configuration, and any additional safeguards in place. Still, SYSTEM-level compromise is precisely why this belongs in normal Windows patch-management work rather than the “we’ll circle back next quarter” pile.

Abstract illustration of connected devices separated by a protected security boundary. CVE-2026-69340 at a glance​

  • Title: Windows NTFS Elevation of Privilege Vulnerability
  • Severity: Important
  • CVSS base score: 7.1
  • CVSS temporal score: 6.2
  • CVSS vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
  • CWE: CWE-122, CWE-125
  • Description: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
  • Publicly disclosed: No
  • Exploited: No
  • Customer action required: Yes

Microsoft’s formal advisory characterizes the weakness as follows: “Windows NTFS Elevation of Privilege Vulnerability: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.”

The two listed weakness categories matter:

  • CWE-122 covers heap-based buffer overflow conditions, where memory allocated on the heap is written beyond its intended boundary.
  • CWE-125 covers out-of-bounds reads, where software accesses memory outside the appropriate buffer range.

These are memory-safety errors, the sort that can turn ordinary file-system processing into a privilege-escalation opportunity when an attacker has the required access and can satisfy the exploit’s environmental conditions.

What Microsoft says about exploitation​

Microsoft states that a successful attack could yield SYSTEM privileges. That would let an attacker operate beyond the permissions of a normal user or service account, potentially changing protected settings, accessing data, installing software, or interfering with security controls on the affected device.

The CVSS vector indicates a network attack vector (AV:N), low privileges required (PR:L), and user interaction required (UI:R). But the vector also assigns high attack complexity (AC:H). Microsoft explains that this means successful exploitation requires a deep understanding of the system and is not guaranteed; it depends on factors that can include the environment, system configuration, and the presence of additional security measures.

In short: the attacker needs a foothold and a carefully prepared route, but the destination—SYSTEM—is not one administrators should leave open.

Affected Windows products and fixed builds​

Apply the update matching the Windows release and architecture in your environment. The build number is a useful compliance check after deployment.

Affected productUpdateFixed build
Windows 10 Version 1607 for 32-bit Systems (x86)KB512309910.0.14393.9512
Windows 10 Version 1607 for x64-based SystemsKB512309910.0.14393.9512
Windows 10 Version 1809 for 32-bit Systems (x86)KB512287610.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsKB512287610.0.17763.9245
Windows 10 Version 21H2 for 32-bit Systems (x86)KB512287810.0.19044.7725
Windows 10 Version 21H2 for ARM64-based SystemsKB512287810.0.19044.7725
Windows 10 Version 21H2 for x64-based SystemsKB512287810.0.19044.7725
Windows 10 Version 22H2 for 32-bit Systems (x86)KB512287810.0.19045.7725
Windows 10 Version 22H2 for ARM64-based SystemsKB512287810.0.19045.7725
Windows 10 Version 22H2 for x64-based SystemsKB512287810.0.19045.7725
Windows 11 Version 23H2 for ARM64-based SystemsKB512288010.0.22631.7582
Windows 11 Version 23H2 for x64-based SystemsKB512288010.0.22631.7582
Windows 11 Version 24H2 for ARM64-based SystemsKB512400810.0.26100.9445
Windows 11 Version 24H2 for x64-based SystemsKB512400810.0.26100.9445
Windows 11 Version 25H2 for ARM64-based SystemsKB512400810.0.26200.9445
Windows 11 Version 25H2 for x64-based SystemsKB512400810.0.26200.9445
Windows 11 Version 26H1 for ARM64-based SystemsKB512401210.0.28000.2954
Windows 11 version 26H1 for x64-based SystemsKB512401210.0.28000.2954
Windows Server 2012 (Server Core installation) (x64)KB51230656.2.9200.26349
Windows Server 2012 (x64)KB51230656.2.9200.26349
Windows Server 2012 R2 (Server Core installation) (x64)KB51230666.3.9600.23398
Windows Server 2012 R2 (x64)KB51230666.3.9600.23398
Windows Server 2016 (Server Core installation) (x64)KB512309910.0.14393.9512
Windows Server 2016 (x64)KB512309910.0.14393.9512
Windows Server 2019 (Server Core installation) (x64)KB512287610.0.17763.9245
Windows Server 2019 (x64)KB512287610.0.17763.9245
Windows Server 2022 (Server Core installation) (x64)KB512288210.0.20348.5622
Windows Server 2022 (x64)KB512288210.0.20348.5622
Windows Server 2025 (Server Core installation) (x64)KB512287110.0.26100.33438
Windows Server 2025 (x64)KB512287110.0.26100.33438

Required remediation​

For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5123099 to reach fixed build 10.0.14393.9512.

For Windows 10 Version 1607 for x64-based Systems, install KB5123099 to reach fixed build 10.0.14393.9512.

For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5122876 to reach fixed build 10.0.17763.9245.

For Windows 10 Version 1809 for x64-based Systems, install KB5122876 to reach fixed build 10.0.17763.9245.

For Windows 10 Version 21H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19044.7725.

For Windows 10 Version 21H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.

For Windows 10 Version 21H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.

For Windows 10 Version 22H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19045.7725.

For Windows 10 Version 22H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.

For Windows 10 Version 22H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.

For Windows 11 Version 23H2 for ARM64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.

For Windows 11 Version 23H2 for x64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.

For Windows 11 Version 24H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.

For Windows 11 Version 24H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.

For Windows 11 Version 25H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.

For Windows 11 Version 25H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.

For Windows 11 Version 26H1 for ARM64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.

For Windows 11 version 26H1 for x64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.

For Windows Server 2012 (Server Core installation) (x64), install KB5123065 to reach fixed build 6.2.9200.26349.

For Windows Server 2012 (x64), install KB5123065 to reach fixed build 6.2.9200.26349.

For Windows Server 2012 R2 (Server Core installation) (x64), install KB5123066 to reach fixed build 6.3.9600.23398.

For Windows Server 2012 R2 (x64), install KB5123066 to reach fixed build 6.3.9600.23398.

For Windows Server 2016 (Server Core installation) (x64), install KB5123099 to reach fixed build 10.0.14393.9512.

For Windows Server 2016 (x64), install KB5123099 to reach fixed build 10.0.14393.9512.

For Windows Server 2019 (Server Core installation) (x64), install KB5122876 to reach fixed build 10.0.17763.9245.

For Windows Server 2019 (x64), install KB5122876 to reach fixed build 10.0.17763.9245.

For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622.

For Windows Server 2022 (x64), install KB5122882 to reach fixed build 10.0.20348.5622.

For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438.

For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438.

Practical deployment priorities​

Organizations should treat this as a standard security-update deployment with a priority appropriate to systems that handle shared files, network-accessible storage, or workloads where authorized users or service accounts have broad access. The disclosed conditions do not turn every Windows device into an instant emergency, but privilege escalation is often the step that transforms a limited intrusion into a much more damaging one.

For administrators, the concrete task is simple:

  1. Identify affected client and server versions, including Server Core deployments.
  2. Deploy the matching cumulative update through the organization’s normal servicing channel.
  3. Confirm that devices report the fixed build listed above.
  4. Investigate update failures promptly, especially on older Windows Server and Windows 10 estates where servicing exceptions and deferred maintenance are more common.

The key takeaway is refreshingly unglamorous: patch the NTFS issue, validate the resulting build, and move on to the next item in the queue. In security, boring and complete is often better than dramatic and late.

 

References

  1. Official MSRC or vendor evidence api.msrc.microsoft.com
  2. Official MSRC or vendor evidence msrc.microsoft.com
  3. Official MSRC or vendor evidence api.msrc.microsoft.com