Yunpeng Tian & Gongming Wang

Breaking NTFS at Scale: From an Unmapped Attack Surface to SYSTEM

Abstract

NTFS has all the qualities of an attractive research target: it is over thirty years old, written in C, enormously complex, and every time a volume comes online the kernel rebuilds its state from attacker-authored on-disk metadata in SYSTEM context. Bugs in it surface every few months. But look at how they arrive: one opcode here, one parser there, years apart, each found and patched on its own. Public NTFS research has largely treated these bugs in isolation. We study the on-disk attack surface systematically.

So we mapped it, then built a pipeline to mine it at scale, generating structurally valid, checksum-correct metadata to get past the gates where ordinary coverage-guided fuzzing stalls. It produced more than thirty NTFS kernel memory-corruption bugs, all confirmed by Microsoft, and a large part of what took us to #1 on the Q2 2026 Windows MSRC leaderboard.

Most of them are instances of a single bug class we call validator/sink drift, where the code that checks an on-disk field and the code that uses it disagree about what that field means. This pattern persists across point fixes, which is why several of our bugs sit in the very functions Microsoft had recently patched.

In this talk, we will show how the NTFS vulnerabilities we found can be exploited to elevate a normal user to SYSTEM.

BIO

Yunpeng Tian is currently a Ph.D. student at the Department of Computing, The Hong Kong Polytechnic University (PolyU). His research primarily focuses on system security, Windows internals, and vulnerability discovery.

He has a strong academic track record, having published multiple papers in top-tier computer science conferences and journals. His recent research has been accepted by prestigious venues including USENIX Security, NDSS, ACM CCS, ASE, and ACM TOSEM.

Beyond academia, he is an active independent vulnerability researcher dedicated to exploring technically compelling, real-world security flaws. His work has led to the discovery of hundreds of real-world vulnerabilities, earning him the title of Microsoft Security Response Center (MSRC) Most Valuable Researcher (MVR). He has consistently appeared on the MSRC leaderboards, ranking 27th globally (9th for Windows) on the 2026 MVR leaderboard, and notably securing 4th place overall and 1st place on the Windows leaderboard in Q2 2026.

GongMing Wang (wgg) is an undergraduate security researcher at Huazhong University of Science and Technology and an MSRC Windows Most Valuable Researcher (MVR). His work focuses on vulnerability discovery and exploitation. He is also a member of the L3HSEC CTF team, specializing in binary exploitation, and reverse engineering.