Sceawere

Vulnerability Detail

CVE-2026-62793UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Windows NTFS Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
7h ago
Vendor
Microsoft
Product
Windows 10 Version 1607
Attack Type
CWE-126: Buffer Over-read
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-08-11T17:18:33.180Z",
  "pubdate": "2026-08-11T17:18:33.180Z",
  "executiveSummary": "This vulnerability involves a buffer over-read flaw residing within the Windows NTFS file system component.\nThe primary security impact of this flaw is local information disclosure, allowing an unauthorized read of out-of-bounds memory regions associated with file system operations.\nThe affected system is the Windows operating system, specifically targeting the NTFS driver and kernel-level file parsing mechanisms.\nThe risk implications include the potential leakage of sensitive kernel memory contents or residual data, which could be leveraged by malicious actors to facilitate more complex multi-stage attacks, such as bypassing defense-in-depth controls like Address Space Layout Randomization (ASLR).\nRegarding attacker capabilities, the threat actor must already possess local access to the target system.\nExploitation requirements stipulate that the attacker must be an authorized user locally on the machine, capable of interacting with the vulnerable file system structures or issuing specific system calls and input/output control requests to trigger the buffer over-read condition.",
  "technicalDetails": "The root cause of the vulnerability stems from improper bounds checking within the Windows NTFS driver when processing specific file system requests or parsing malformed metadata structures.\nSpecifically, the vulnerable component fails to adequately validate the length of input data relative to the allocated buffer size, resulting in a buffer over-read condition where the reading mechanism reads past the intended boundary of the allocated buffer into adjacent memory regions.\nThe affected component is the kernel-mode NTFS file system driver responsible for handling low-level disk operations and data structure parsing.\nThe authentication and privilege requirements mandate that the attacker possesses local execution capabilities on the target system with valid authorization, although elevated privileges may or may not be required depending on the precise attack vector and interface used to trigger the over-read.\nNetwork exposure is non-existent as the vulnerability is strictly local and cannot be exploited remotely over a network protocol.\nThe attack flow begins when the local attacker crafts or identifies a scenario where the NTFS driver processes a request that triggers the flawed bounds checking logic.\nDuring payload behavior, the vulnerable function reads beyond the allocated buffer boundaries, accessing adjacent kernel memory or sensitive cache structures.\nThe post-exploitation impact involves the unauthorized disclosure of information, where the contents of the adjacent memory are returned to the user space or exposed through system logs, error messages, or application outputs, thereby leaking memory contents that may contain sensitive data structures, cryptographic keys, or pointers useful for subsequent exploit chains."
}
CVE-2026-62793: Windows NTFS Information Disclosure (MEDIUM Severity, CVSS: 5.5) - Sceawere