CVE-2026-50402
HIGHMicrosoft Windows 10 Version 1607 - NTFS Elevation of Privilege Vulnerability
Title source: ruleExploitation Summary
EIP tracks 1 public exploit for CVE-2026-50402. PoCs published by SY115.
AI-analyzed exploit summary Detailed technical analysis of CVE-2026-50402, a signed/unsigned integer comparison bug in `ntfs.sys!NtfsIsBootSectorNtfs` leading to a DoS and kernel write primitive via NTFS log file replay. The writeup includes root cause analysis, patch diffs, crash dump analysis, and proof-of-concept for permission tampering through crafted VHDX files.
Description
Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.
Exploits (1)
Detailed technical analysis of CVE-2026-50402, a signed/unsigned integer comparison bug in `ntfs.sys!NtfsIsBootSectorNtfs` leading to a DoS and kernel write primitive via NTFS log file replay. The writeup includes root cause analysis, patch diffs, crash dump analysis, and proof-of-concept for permission tampering through crafted VHDX files.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H