CVE-2026-73024
largeLocal Privilege Escalation via Heap Overflow in Windows Services for NFS ONCRPC XDR Driver
CVE-2026-73024 is a heap-based buffer overflow (CWE-122) in the ONCRPC XDR driver used by Microsoft's Windows Services for NFS, the optional component that lets Windows interoperate with NFS file shares. An attacker who already holds limited privileges on the local machine can trigger the overflow through the NFS/ONCRPC code path, corrupting heap memory in the driver. Successful exploitation yields local elevation of privileges, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8, local vector, low privileges, no user interaction). Only Windows systems where Services for NFS (Client for NFS / Server for NFS) is installed and enabled are affected, and this feature is off by default on most Windows installations. There is currently no known exploitation in the wild, no public proof-of-concept, and a low EPSS of 0.2% (16th percentile).
What to do: Deploy Microsoft's security update addressing CVE-2026-73024 to all supported Windows releases via Windows Update/WSUS as soon as it is available. Audit systems for the feature — on Windows Server run Get-WindowsFeature FS-NFS-Service, and on Windows clients check Optional Features for 'Services for NFS' — and disable or remove it where NFS interoperability is not required. Because exploitation requires only low local privileges, prioritize patching multi-user hosts such as RDS servers and shared workstations.
| Microsoft Windows Services for NFS (ONCRPC XDR driver) on supported Windows client and server releases | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.