Junglewise Threat Intelligence

CVE-2026-71330: Microsoft Windows Services for NFS ONCRPC XDR Driver information disclosure

CVE-2026-71330 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

Windows Services for NFS provides network file sharing capabilities for Windows systems. A vulnerability in its ONCRPC XDR Driver allows an unauthorized attacker to disclose sensitive system information over the network, potentially exposing configuration details and other confidential data without requiring authentication or special privileges.

Technical details

This is an information disclosure vulnerability (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) in the ONCRPC XDR Driver component of Windows Services for NFS. The vulnerability allows unauthorized attackers to access sensitive system information over a network without authentication. The attack vector is network-based and does not require user interaction or local access. An attacker can exploit this to retrieve confidential system details that could be used for reconnaissance or further targeted attacks.

Affected products

  • Microsoft Windows Services for NFS

Timeline

  • 2026-09-08: disclosed

References

Related threats