Junglewise Threat Intelligence

CVE-2026-78445: Microsoft Windows Services for NFS use-after-free in ONCRPC XDR driver

CVE-2026-78445 · Severity: critical · CVSS 9.8 · Published 2026-09-08

Executive brief

Windows Services for NFS is a network component that allows Windows systems to access files on Unix/Linux servers. A use-after-free vulnerability in the ONCRPC XDR driver allows an attacker to execute arbitrary code remotely on affected systems without authentication, potentially giving them full control over the machine and access to all corporate data.

Technical details

A use-after-free memory vulnerability exists in the ONCRPC XDR (External Data Representation) driver component of Windows Services for NFS. The vulnerability allows remote code execution over the network without requiring authentication or user interaction. An attacker can send specially crafted network packets to trigger the use-after-free condition, leading to arbitrary code execution with the privileges of the NFS service. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows Services for NFS

Timeline

  • 2026-09-08: disclosed

References

Related threats