CVE-2026-69595
9.8Microsoft · Windows Server
A use after free vulnerability in the Windows Services for NFS ONCRPC XDR Driver allows unauthenticated remote attackers to execute arbitrary code.
Executive summary
A critical use after free vulnerability in the Windows Services for NFS ONCRPC XDR Driver enables unauthenticated remote code execution on multiple versions of Windows Server.
Vulnerability
This is a use after free flaw (CWE-416) within the ONCRPC XDR Driver component of Windows Services for NFS. An unauthenticated attacker can trigger this vulnerability over a network to achieve remote code execution.
Business impact
The CVSS score of 9.8 reflects the critical nature of this vulnerability, as it allows full system compromise without requiring user interaction or authentication. Successful exploitation grants attackers complete control over the affected server, potentially leading to unauthorized data exfiltration, service disruption, and lateral movement within the network.
Remediation
Immediate Action: Apply the security updates provided by Microsoft in the official advisory to bring the affected systems to the specified fixed versions.
Proactive Monitoring: Monitor network traffic for anomalous RPC (Remote Procedure Call) activity and inspect system logs for unusual process execution patterns or service crashes related to the NFS driver.
Compensating Controls: If immediate patching is not feasible, restrict access to the NFS service by implementing network-level access control lists (ACLs) or by placing the service behind a firewall to block untrusted traffic.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the critical severity and the potential for full system compromise, organizations should prioritize the deployment of the vendor-supplied patches across all affected Windows Server environments. Ensure that all instances of Windows Server 2012, 2012 R2, and 2016 are updated to the required versions to eliminate the underlying flaw and prevent potential exploitation.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section