Junglewise Threat Intelligence

CVE-2026-71334: Microsoft Windows NFS Portmapper heap-based buffer overflow

CVE-2026-71334 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows NFS Portmapper is a network service that manages port mappings for Network File System (NFS) connections on Windows servers. A heap-based buffer overflow vulnerability allows an authenticated local attacker to execute arbitrary code with elevated privileges, potentially compromising the entire system.

Technical details

The vulnerability is a heap-based buffer overflow in the Windows NFS Portmapper service. An authorized attacker with local access can trigger the overflow condition to corrupt heap memory and achieve privilege escalation. The attack requires local authentication and execution on the affected system. Successful exploitation allows an attacker to run arbitrary code with SYSTEM privileges. Microsoft has released security updates to patch this vulnerability.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats