ZeroHour

CVE-2026-73024

large

Local Privilege Escalation via Heap Overflow in Windows Services for NFS ONCRPC XDR Driver

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-73024 is a heap-based buffer overflow (CWE-122) in the ONCRPC XDR driver used by Microsoft's Windows Services for NFS, the optional component that lets Windows interoperate with NFS file shares. An attacker who already holds limited privileges on the local machine can trigger the overflow through the NFS/ONCRPC code path, corrupting heap memory in the driver. Successful exploitation yields local elevation of privileges, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8, local vector, low privileges, no user interaction). Only Windows systems where Services for NFS (Client for NFS / Server for NFS) is installed and enabled are affected, and this feature is off by default on most Windows installations. There is currently no known exploitation in the wild, no public proof-of-concept, and a low EPSS of 0.2% (16th percentile).

What to do: Deploy Microsoft's security update addressing CVE-2026-73024 to all supported Windows releases via Windows Update/WSUS as soon as it is available. Audit systems for the feature — on Windows Server run Get-WindowsFeature FS-NFS-Service, and on Windows clients check Optional Features for 'Services for NFS' — and disable or remove it where NFS interoperability is not required. Because exploitation requires only low local privileges, prioritize patching multi-user hosts such as RDS servers and shared workstations.

Affected
Microsoft Windows Services for NFS (ONCRPC XDR driver) on supported Windows client and server releases
Estimated exposure
largeon the order of 100,000–1,000,000 Windows systems worldwide with Services for NFS enabled (order-of-magnitude estimate) — Services for NFS is a non-default optional feature concentrated in mixed Unix/Windows enterprise estates, so the estimate is derived from typical enterprise deployment patterns rather than public scan counts, and no hard install-base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.