Sergey Tarasov, a specialist at the Positive Technologies Expert Security Center (PT ESC), has discovered three vulnerabilities within the NTFS file system driver. These flaws affect 30 versions of the Windows operating system, including both desktop and server editions. Tens of millions of Russian users are at risk, including those running the widely used Windows 10 and 11. Based on data from Rosstat and Statcounter, at least 40 million computers in the country run on these systems. The researcher reported the flaws to the vendor under a responsible disclosure policy, and Microsoft has already released security updates.
Windows remains the most popular operating system globally: according to Statcounter, it holds over 70% of the desktop OS market. In Russia, it is installed on over 85% of computers. The most widely adopted versions are Windows 10 (approximately 22 million devices) and Windows 11 (around 18.3 million). This amounts to roughly 40 million computers that are potentially vulnerable to the discovered flaws.
In the enterprise sector, Windows is also one of the most widely used operating systems for server infrastructure. According to Positive Technologies' threat intelligence, there are over 6.5 million vulnerable internet-exposed devices running Windows Server worldwide. Russia ranks in the top six countries for Windows Server 2025 installations (at least 160,000), the top 10 for Windows Server 2019 (73,000), and the top 13 for Windows Server 2022 (71,000). Furthermore, a significant portion of unprotected servers running these three OS versions is located in the U.S. (1.3 million), China (1.8 million), and Germany (1.2 million).