ZeroHour

CVE-2026-69595

large

Use-After-Free RCE in Windows Services for NFS ONCRPC XDR Driver

CVSS 3.1
9.8 critical
EPSS
1%p63
Published
()
Modified
AI analysis

CVE-2026-69595 is a use-after-free memory corruption flaw (CWE-416) in the ONCRPC XDR driver of Microsoft's Windows Services for NFS (Network File System). An unauthenticated remote attacker can trigger it by sending crafted ONCRPC/XDR network traffic to a machine running the NFS service, causing the driver to reference freed memory. Successful exploitation yields arbitrary code execution on the target with full confidentiality, integrity, and availability impact (CVSS 9.8, no credentials or user interaction required). Affected organizations are those that have installed and enabled the optional Services for NFS interoperability feature, primarily on Windows Server in mixed Windows/Unix file-sharing environments; the source data does not specify affected version ranges. No exploitation is publicly known at this time: the flaw is not in CISA's KEV, no public proof-of-concept exists, and EPSS estimates only a 1.1% chance of exploitation within 30 days; Microsoft patched it as part of its record 974-flaw release.

What to do: Apply Microsoft's update for this CVE from the 974-flaw patch release as a priority. If the NFS feature is not needed, disable or remove Services for NFS; otherwise restrict ONCRPC/NFS traffic (typical ports 2049 and 111, TCP and UDP) to trusted networks only. Audit your Windows servers for whether the Services for NFS feature is installed, since it is optional and easily overlooked.

Affected
Microsoft Windows Services for NFS (ONCRPC XDR driver)
Estimated exposure
large≈10,000–100,000 Windows deployments with the Services for NFS feature enabled (rough estimate) — Services for NFS is an optional Windows interoperability component used by a minority of Windows Server deployments for Unix/NAS file sharing, and while public internet scans show hundreds of thousands of NFS endpoints (port 2049), Windows…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

Microsoft's September Patch Tuesday fixed a record 974 flaws, including two Windows privilege-escalation zero-days actively exploited and added to CISA's KEV catalog.

Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities (999 including 25 non-Microsoft CVEs), with over 110 rated critical; 723 affect Windows and 111 affect Office. Two Windows privilege-escalation zero-days are actively exploited: CVE-2026-85880, an ALPC heap-based buffer overflow, and CVE-2026-81963, an improper link resolution flaw in the Windows Update Stack, both allowing attackers to gain SYSTEM privileges. CISA added both flaws to its KEV catalog, giving federal civilian agencies until September 22, 2026 to apply fixes. Volexity, Proofpoint, MSTIC, and independent researchers were credited with the reports; notable additional fixes include network-reachable RCEs in Exchange, SharePoint, SQL Server, Remote Desktop Services, DNS, and DHCP.

The Hacker News · 6d agoExploit / PoC in the wildCVE-2026-85880CVE-2026-81963CVE-2026-55007+9 CVEs