ZeroHour

CVE-2026-83989

moderate

Out-of-Bounds Read DoS in Microsoft Windows Services for NFS ONCRPC XDR Driver

CVSS 3.1
7.5 high
EPSS
<1%p57
Published
()
Modified
AI analysis

CVE-2026-83989 is an out-of-bounds read (CWE-125) in the ONCRPC XDR driver of Microsoft's Windows Services for NFS, addressed in Microsoft's September 2026 Patch Tuesday release. A remote, unauthenticated attacker can trigger it by sending crafted ONC RPC/XDR network requests to a host running the NFS service, causing the driver to read past the end of an allocated buffer. Successful exploitation crashes the NFS service, yielding denial of service only; the CVSS vector (C:N/I:N/A:H) confirms there is no data disclosure or tampering impact. Any Windows system with Services for NFS installed and enabled is affected, but practical exposure is limited to environments that actually use this optional feature, particularly where the NFS service is reachable from untrusted networks. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a 0.9% 30-day exploitation probability (57th percentile), so no active exploitation is currently reported.

What to do: Apply the September 2026 Patch Tuesday security updates from Microsoft on any Windows systems with Services for NFS installed, checking Microsoft's advisory for the affected Windows versions and fixed builds. Inventory systems for the NFS feature/role and confirm whether the NFS/ONC RPC service is reachable from untrusted networks, restricting access with firewall rules or trusted-subnet limits where patching is delayed. Continue monitoring Microsoft's advisory and CISA KEV, since no public PoC or in-the-wild exploitation is known as of this analysis.

Affected
Microsoft Windows Services for NFS (ONCRPC XDR driver)
Estimated exposure
moderate≈10,000–100,000 Windows servers worldwide with Services for NFS enabled, of which only a small fraction have the NFS service exposed to untrusted networks — Services for NFS is an optional Windows feature that is not enabled by default, and internet-wide scans of NFS (port 2049) are dominated by non-Windows hosts, so only a small subset of the very large Windows install base plausibly runs the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

Microsoft Patch Tuesday Update September 2026 – 974 Vulnerabilities Fixed, Including 2 Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities across Windows and Office, including two actively exploited Windows privilege-escalation zero-days.

Microsoft's September 2026 Patch Tuesday addresses 974 vulnerabilities spanning Windows, Office, SQL Server, SharePoint, Exchange, Azure, and developer tools. Two Windows zero-days are confirmed exploited in attacks: CVE-2026-85880, a Windows ALPC elevation-of-privilege flaw, and CVE-2026-81963, a Windows Update Stack privilege-escalation flaw involving link following. The release also includes Critical fixes for Windows Secure Kernel Mode, VBS Enclave, Excel, and Word.

Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities and 2 Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including two zero-days already exploited in the wild.

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, and Azure components, including two zero-days already exploited in the wild. CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, is flagged as an exploited zero-day. The release includes numerous remote code execution and information disclosure fixes for Microsoft Excel and Word, plus patches for the Windows kernel, ALPC, Print Spooler, ReFS, Entra ID, and Azure CLI.

GBHackers · 7d agoAdvisory in the wildCVE-2026-85880CVE-2026-85877CVE-2026-85875+27 CVEs