PT-2026-58147 · Microsoft · Windows
CVE-2026-49172
·
Published
2026-07-14
·
Updated
2026-07-23
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows 10 (affected versions not specified)
Windows 11 (affected versions not specified)
Windows Server 2019 (affected versions not specified)
Windows Server 2022 (affected versions not specified)
Windows Server 2025 (affected versions not specified)
Description
A heap-based buffer overflow exists in the Windows FTP Service. This flaw allows an unauthorized remote attacker to execute arbitrary code and affect the system over a network. A heap-based buffer overflow occurs when a program writes more data to a heap memory block than it can hold, potentially leading to memory corruption.
Recommendations
Update Windows 10 to the July 2026 Patch Tuesday release.
Update Windows 11 to the July 2026 Patch Tuesday release.
Update Windows Server 2019 to the July 2026 Patch Tuesday release.
Update Windows Server 2022 to the July 2026 Patch Tuesday release.
Update Windows Server 2025 to the July 2026 Patch Tuesday release.
Fix
DoS
RCE
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows