Executive brief
Windows Services for NFS is a network component that allows Windows systems to access files on Unix/Linux servers. A use-after-free vulnerability in the ONCRPC XDR driver allows an attacker to execute arbitrary code remotely on affected systems without authentication, potentially giving them full control over the machine and access to all corporate data.
Technical details
A use-after-free memory vulnerability exists in the ONCRPC XDR (External Data Representation) driver component of Windows Services for NFS. The vulnerability allows remote code execution over the network without requiring authentication or user interaction. An attacker can send specially crafted network packets to trigger the use-after-free condition, leading to arbitrary code execution with the privileges of the NFS service. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows Services for NFS
Timeline
- 2026-09-08: disclosed