Skip to finding
important · Physical — Windows

Crafted NTFS storage can trigger kernel code execution when attached to a Windows machine.

Affects

Microsoft Windows 10, Windows 11, and Windows Server systems whose NTFS driver processes attacker-supplied storage

Physical attachment through an accepted storage interface can reach three NTFS heap overflows without credentials or user interaction.

Detail and 2 sources

We do not know the malformed structures or final instruction-control mechanics.

Chain to watch
Prepare crafted NTFS storage.→↓Attach it to an affected Windows machine.→↓NTFS parsing reaches a kernel heap overflow.→↓The malformed NTFS structures and final instruction-control steps are not public.
Unverified chainDiff the fixed ntfs.sys builds and reproduce representative media under kernel tracing.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 10, 2026