Executive brief
Windows NFS Portmapper is a network service that manages port mappings for Network File System (NFS) connections on Windows servers. A heap-based buffer overflow vulnerability allows an authenticated local attacker to execute arbitrary code with elevated privileges, potentially compromising the entire system.
Technical details
The vulnerability is a heap-based buffer overflow in the Windows NFS Portmapper service. An authorized attacker with local access can trigger the overflow condition to corrupt heap memory and achieve privilege escalation. The attack requires local authentication and execution on the affected system. Successful exploitation allows an attacker to run arbitrary code with SYSTEM privileges. Microsoft has released security updates to patch this vulnerability.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed