Use-after-free in Windows Services for NFS ONCRPC XDR Driver enables local code execution
AI analysis
CVE-2026-70585 is a use-after-free (CWE-416) memory-safety flaw in the Windows Services for NFS ONCRPC XDR driver, the Windows component that handles ONCRPC/XDR protocol processing for NFS interoperability. An authorized attacker with low privileges on the host can trigger the flaw locally with no user interaction, though exploitation is rated high attack complexity, and successful exploitation yields local code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.0 High). Exposure is limited to Windows systems where the optional Services for NFS / Client for NFS feature is enabled, since the vulnerable driver is tied to that NFS interoperability functionality. As of the September 2026 Patch Tuesday release, there is no known in-the-wild exploitation, no public proof of concept, the flaw is not in CISA KEV, and EPSS assigns a low 0.3% 30-day exploitation probability.
What to do: Apply Microsoft's September 2026 Patch Tuesday cumulative updates to Windows hosts, prioritizing servers and workstations where the Client for NFS / Services for NFS feature is enabled and untrusted local users can log on. Where NFS interoperability is not required, disabling the optional Services for NFS feature is a reasonable interim mitigation. Confirm remediation via the Windows update history for the September 2026 release, and note that high attack complexity plus low EPSS make this urgent-but-not-critical patching.
Affected
| Microsoft Windows Services for NFS ONCRPC XDR Driver (Services for NFS / Client for NFS component) | — |
Estimated exposure
largeon the order of 100,000 Windows hosts with the optional Client for NFS/Services for NFS feature enabled (estimated) — The ONCRPC XDR driver ships with Windows, but Services for NFS / Client for NFS is a non-default optional feature used mainly in mixed Windows/UNIX enterprise file-sharing environments, so only a small fraction of the >1B Windows install…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.