ZeroHour

CVE-2026-78445

large

Use-after-free RCE in Windows Services for NFS ONCRPC XDR Driver

CVSS 3.1
9.8 critical
EPSS
<1%p58
Published
()
Modified
AI analysis

CVE-2026-78445 is a use-after-free vulnerability (CWE-416) in the ONCRPC XDR driver that is part of Windows Services for NFS, Microsoft's optional Network File System interoperability component. An unauthenticated remote attacker can trigger the flaw by sending network traffic that is processed by the driver's ONCRPC/XDR handling, causing reuse of freed memory and resulting in arbitrary code execution. Successful exploitation grants the attacker code execution on the target host with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 9.8, critical). Only Windows systems where the optional Services for NFS feature has been installed and enabled are exposed, since it is not part of a default Windows installation. As of now there is no known exploitation in the wild, no public proof-of-concept, and the issue is not in CISA KEV; EPSS estimates roughly a 0.9% probability of exploitation within the next 30 days.

What to do: Inventory Windows hosts for the Services for NFS optional features (Client for NFS / Server for NFS) and for active NFS-related services and listeners (e.g., NFS on port 2049, ONCRPC portmapper on port 111), and prioritize those systems for Microsoft's patch for CVE-2026-78445 once released, as specific affected builds are not enumerated in the available data. As interim mitigation, disable or remove Services for NFS on systems that do not need it, or restrict network access to the NFS/ONCRPC endpoints to trusted hosts only. No public exploit is known, so there is no indication of in-the-wild exploitation at this time.

Affected
Microsoft Windows Services for NFS (ONCRPC XDR Driver)
Estimated exposure
large~10,000-100,000 Windows hosts with Services for NFS enabled (exact count unknown) — Services for NFS is an opt-in, non-default Windows feature used mainly in enterprise Unix/NFS interoperability scenarios, so only a small fraction of Windows' billion-plus installs is plausibly affected, on the order of tens of thousands…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.