Junglewise Threat Intelligence

CVE-2026-83989: Microsoft Windows Services for NFS ONCRPC XDR Driver out-of-bounds read

CVE-2026-83989 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

Windows Services for NFS is a component that enables Windows systems to communicate with NFS (Network File System) servers commonly used in Unix and Linux environments. An out-of-bounds read vulnerability in the ONCRPC XDR driver allows a remote attacker to crash the NFS service, disrupting file access for users and potentially affecting business operations that depend on NFS connectivity.

Technical details

The vulnerability is an out-of-bounds read in the ONCRPC XDR (External Data Representation) driver component of Windows Services for NFS. The flaw allows an unauthenticated remote attacker to send specially crafted network packets to trigger the out-of-bounds read, resulting in a denial-of-service condition. No user interaction or prior authentication is required; the vulnerability is network-accessible. An attacker can exploit this to cause the NFS service to crash or become unresponsive. A patch is available from Microsoft.

Affected products

  • Microsoft Windows Services for NFS <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats