CVE-2026-69772
largeHeap-Based Buffer Overflow Allows Remote Code Execution in Windows NFS
CVE-2026-69772 is a heap-based buffer overflow (CWE-122) in the Windows Network File System (NFS) component of Microsoft Windows. A remote, unauthorized attacker can trigger the flaw by sending crafted network traffic to, or interacting over the network with, the vulnerable NFS component; the CVSS vector indicates network reachability with no privileges required, though some user interaction is involved. Successful exploitation allows the attacker to execute arbitrary code on the target system with high impact on confidentiality, integrity, and availability. Exposure is limited to Windows systems where the optional NFS client or server feature is enabled, since most Windows installations do not have this component active by default; specific affected Windows version ranges are not provided in the source data. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS puts 30-day exploitation probability at roughly 0.8% (53rd percentile), indicating no confirmed exploitation in the wild.
What to do: Apply Microsoft's security update for CVE-2026-69772 through Windows Update as soon as it is released, prioritizing hosts with the Client for NFS or Services for NFS feature enabled. As an interim mitigation, disable the NFS client/server where it is not needed and restrict NFS network access (e.g., TCP/UDP port 2049) to trusted hosts only. Consult Microsoft's advisory for the exact affected Windows versions, since the source data does not enumerate them.
| Microsoft Windows (Network File System component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Network File System allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.