ZeroHour

CVE-2026-70585

large

Use-after-free in Windows Services for NFS ONCRPC XDR Driver enables local code execution

CVSS 3.1
7.0 high
EPSS
<1%p18
Published
()
Modified
AI analysis

CVE-2026-70585 is a use-after-free (CWE-416) memory-safety flaw in the Windows Services for NFS ONCRPC XDR driver, the Windows component that handles ONCRPC/XDR protocol processing for NFS interoperability. An authorized attacker with low privileges on the host can trigger the flaw locally with no user interaction, though exploitation is rated high attack complexity, and successful exploitation yields local code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.0 High). Exposure is limited to Windows systems where the optional Services for NFS / Client for NFS feature is enabled, since the vulnerable driver is tied to that NFS interoperability functionality. As of the September 2026 Patch Tuesday release, there is no known in-the-wild exploitation, no public proof of concept, the flaw is not in CISA KEV, and EPSS assigns a low 0.3% 30-day exploitation probability.

What to do: Apply Microsoft's September 2026 Patch Tuesday cumulative updates to Windows hosts, prioritizing servers and workstations where the Client for NFS / Services for NFS feature is enabled and untrusted local users can log on. Where NFS interoperability is not required, disabling the optional Services for NFS feature is a reasonable interim mitigation. Confirm remediation via the Windows update history for the September 2026 release, and note that high attack complexity plus low EPSS make this urgent-but-not-critical patching.

Affected
Microsoft Windows Services for NFS ONCRPC XDR Driver (Services for NFS / Client for NFS component)
Estimated exposure
largeon the order of 100,000 Windows hosts with the optional Client for NFS/Services for NFS feature enabled (estimated) — The ONCRPC XDR driver ships with Windows, but Services for NFS / Client for NFS is a non-default optional feature used mainly in mixed Windows/UNIX enterprise file-sharing environments, so only a small fraction of the >1B Windows install…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including 113 critical, with two Windows privilege-escalation bugs (CVE-2026-81963, CVE-2026-85880) exploited in the wild.

Microsoft's September 2026 security update addresses 973 vulnerabilities across its product lineup, 113 rated critical, of which 82 are remote code execution flaws. Two vulnerabilities are confirmed exploited in the wild: CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack (CVSS 7.8), and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (CVSS 7.8). Microsoft flags several bugs as more likely to be exploited, including a 9.8 RCE in Windows DNS Server (CVE-2026-69730), an 8.8 RCE in Windows Kerberos (CVE-2026-69676), and a 9.0 EoP in Spring Cloud Azure (CVE-2026-69854). Cisco Talos published accompanying Snort rules to detect exploitation attempts against the prominent flaws.

Cisco Talos · 7d agoAdvisory in the wildCVE-2026-81963CVE-2026-85880CVE-2026-69676+27 CVEs