Executive brief
A critical vulnerability exists in the Network File System (NFS) protocol that allows unauthorized users to bypass security controls. By providing a false user identity, an attacker can gain full access to read or modify any file on the affected server. This could lead to the complete theft of sensitive data, destruction of files, or total system compromise.
Technical details
The Network File System (NFS) protocol contains a fundamental flaw in how it handles user authentication and authorization. An attacker can craft network requests using a spoofed User Identifier (UID) to impersonate any user, including the root user. Because the service relies on the client-provided UID without sufficient server-side verification, the attacker gains full read and write permissions to all files exported by the NFS server. This is a network-based attack that requires no prior authentication, leading to a complete compromise of confidentiality, integrity, and availability.
Affected products
- Generic NFS
Timeline
- 1997-07-01: disclosed: Initial publication date in NVD