CVE-2026-25175
7.8Microsoft · Windows
A local out-of-bounds read vulnerability in the Windows NTFS driver allows an authenticated attacker to elevate privileges on the local system.
Executive summary
A vulnerability in the Windows NTFS driver allows a locally authenticated attacker to elevate their privileges, posing a significant risk to system security and integrity.
Vulnerability
This is an out-of-bounds read vulnerability (CWE-125) within the Windows NTFS driver. An attacker must already have local access and low-level privileges to trigger the flaw and achieve privilege escalation.
Business impact
The ability for a local user to escalate privileges represents a critical threat to the principle of least privilege. With a CVSS score of 7.8, this vulnerability allows an attacker to bypass security boundaries, potentially leading to full system compromise, unauthorized data access, or the deployment of persistent malware within the environment.
Remediation
Immediate Action: Administrators must apply the latest cumulative security updates provided by Microsoft for the specific versions of Windows 10 and Windows 11 listed.
Proactive Monitoring: Monitor system logs for unusual process creation or access patterns that may indicate an attempt to exploit local kernel-mode drivers.
Compensating Controls: Ensure that local user permissions are strictly managed and that non-administrative users are restricted from executing untrusted or arbitrary binaries on the local machine.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a clear path for local privilege escalation which could lead to total system compromise. IT teams should prioritize the deployment of the March 2026 security updates across all affected Windows workstations and servers to mitigate this risk immediately.
More Microsoft CVEs
Sources
- Windows NTFS Elevation of Privilege Vulnerability Vendor advisory