ZeroHour

CVE-2026-71330

niche

Unauthenticated Information Disclosure in Windows Services for NFS ONCRPC XDR Driver

CVSS 3.1
7.5 high
EPSS
<1%p54
Published
()
Modified
AI analysis

Windows Services for NFS's ONCRPC XDR driver exposes sensitive system information to an unauthorized control sphere (CWE-497), letting unauthenticated network attackers read data they should not be able to access. The flaw is triggered remotely over the network with no privileges, no user interaction, and low attack complexity, simply by reaching the affected ONCRPC/XDR service. An attacker gains disclosure of sensitive system information only; there is no integrity or availability impact per the CVSS vector. Affected systems are Windows hosts with the Services for NFS (ONCRPC XDR driver) component installed and reachable over the network, though the specific affected Windows version ranges were not included in the available data. As of this analysis there is no known exploitation in the wild, no public proof-of-concept, and the flaw is not in CISA's KEV catalog; EPSS puts 30-day exploitation probability at 0.8% (54th percentile).

What to do: Apply Microsoft's security update for CVE-2026-71330 when it is released via Windows Update. Until patched, audit Windows hosts (especially servers) for the enabled Services for NFS / Client for NFS feature and restrict or firewall NFS/ONCRPC-related network exposure (e.g., NFS and portmapper ports such as 2049 and 111) to trusted networks, or disable the feature entirely where it is unused.

Affected
Microsoft Windows Services for NFS (ONCRPC XDR Driver)
Estimated exposure
nichelikely tens of thousands of hosts worldwide at most, limited to Windows systems with the optional Services for NFS feature enabled and reachable from untrusted… — Services for NFS / Client for NFS is an optional Windows component used mainly in mixed Windows-UNIX file-sharing environments and is rarely enabled, and even more rarely exposed to untrusted networks, so the exposed install base is far…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network.

Weakness
CWE-497
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.