Junglewise Threat Intelligence

CVE-2026-69595: Microsoft Windows Services for NFS ONCRPC XDR Driver use after free

CVE-2026-69595 · Severity: critical · CVSS 9.8 · Published 2026-09-08

Executive brief

Windows Services for NFS is a Windows component that enables network file sharing using the NFS protocol. A use-after-free vulnerability in the ONCRPC XDR driver allows an attacker to execute arbitrary code remotely over the network without requiring authentication, potentially compromising the entire system.

Technical details

A use-after-free vulnerability exists in the Windows Services for NFS ONCRPC XDR Driver, which handles data serialization/deserialization for NFS network communication. The vulnerability is remotely exploitable over the network without authentication requirements. An attacker can craft a malicious NFS request that triggers memory mismanagement, allowing code execution with the privileges of the NFS service. The network-reachable attack vector combined with lack of authentication requirements creates a high-impact remote code execution risk.

Affected products

  • Microsoft Windows Services for NFS <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats