News

Positive Technologies researcher discovers three vulnerabilities affecting 30 Windows OS versions

Sergey Tarasov, a specialist at the Positive Technologies Expert Security Center (PT ESC), has discovered three vulnerabilities within the NTFS file system driver. These flaws affect 30 versions of the Windows operating system, including both desktop and server editions. Tens of millions of Russian users are at risk, including those running the widely used Windows 10 and 11. Based on data from Rosstat and Statcounter, at least 40 million computers in the country run on these systems. The researcher reported the flaws to the vendor under a responsible disclosure policy, and Microsoft has already released security updates.

Windows remains the most popular operating system globally: according to Statcounter, it holds over 70% of the desktop OS market. In Russia, it is installed on over 85% of computers. The most widely adopted versions are Windows 10 (approximately 22 million devices) and Windows 11 (around 18.3 million). This amounts to roughly 40 million computers that are potentially vulnerable to the discovered flaws.

In the enterprise sector, Windows is also one of the most widely used operating systems for server infrastructure. According to Positive Technologies' threat intelligence, there are over 6.5 million vulnerable internet-exposed devices running Windows Server worldwide. Russia ranks in the top six countries for Windows Server 2025 installations (at least 160,000), the top 10 for Windows Server 2019 (73,000), and the top 13 for Windows Server 2022 (71,000). Furthermore, a significant portion of unprotected servers running these three OS versions is located in the U.S. (1.3 million), China (1.8 million), and Germany (1.2 million).

All three vulnerabilities reside in the NTFS driver, the core component that manages the file system. The security flaws tracked as PT-2026-584471 (CVE-2026-50471; BDU: 2026-07473), PT-2026-58468 (CVE-2026-50494; BDU: 2026-06812), and PT-2026-58283 (CVE-2026-58640; BDU: 2026-07474) affect 30 operating systems across various versions and architectures, including Windows 10 and 11, as well as Windows Server 2016, 2019, 2022, and 2025. The complete list is available in the vendor's official advisories (1, 2, 3). The first two vulnerabilities are considered the most dangerous, both scoring 7.8 on the CVSS 3.1 scale. One of them, PT-2026-58468, could allow attackers to execute arbitrary code, granting them full control over the target machine. The third security flaw received a CVSS 3.1 score of 7.3.

These vulnerabilities allow attackers to bypass security software, which means that malicious activity can remain undetected for extended periods.

To carry out an attack, a threat actor would simply need to trick the victim into opening a specially crafted VHD file—a format typically used for storing backups or transferring large amounts of data. To the user, the file appears to be a standard ZIP folder, and double-clicking it feels no different from opening any other archive. However, concealed within the file is malicious code that, when executed, allows the installation of malware on the device.

1 The vulnerabilities have been registered on the dbugs portal, which aggregates data on vulnerabilities in software and hardware from vendors around the world.

"Based on PT ESC's incident response experience, attackers exploiting these vulnerabilities most often attempt to install spyware that monitors keystrokes, tracks visited websites, and steals passwords. However, they may also pursue other objectives, such as encrypting all files to demand a ransom or hijacking the computer to mine cryptocurrency."

Sergey Tarasov
Sergey TarasovHead of Vulnerability Analysis at the Positive Technologies Expert Security Center

Prior to being patched, these vulnerabilities posed a threat not only to home computers but also to corporate infrastructures. If attackers managed to compromise an employee's workstation, it would provide them with a foothold into the corporate network. From there, they could move laterally across the infrastructure to steal sensitive data and customer databases. For organizations, such malicious actions typically lead to confidential data breaches, disruption of business operations, or outages of critical services.

To identify attacks that could exploit similar vulnerabilities, organizations should deploy a vulnerability management platform such as MaxPatrol VM. MaxPatrol SIEM can detect pre-exploitation activity inside your environment. Using its antivirus engine emulator, MaxPatrol EPP can proactively detect malware attempting to exploit these vulnerabilities. MaxPatrol EDR detects threats across more than 25 operating systems, covering the major versions among the world's top ten most common operating systems, including Windows.

Positive Technologies researchers frequently identify security flaws in Microsoft solutions. Since this research began in 2012, the vendor has patched 15 vulnerabilities identified by the team.

For up-to-date security information, visit the dbugs portal, which aggregates vulnerability data and vendor recommendations for software and hardware from vendors around the world.