Impact
This vulnerability is a heap‑based buffer overflow in the Windows Network File System (NFS) service. The bug arises when the service fails to verify data received from a client, causing an uncontrolled write that can lead to arbitrary code execution or privilege escalation. The flaw is classified under buffer overflow (CWE-122) and arithmetic overflow (CWE-190) weaknesses.
Affected Systems
Affected systems include Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (24H2, 25H2, 26H1), and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025. All installations that enable the Windows NFS Server component, whether full or Server Core, are vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity flaw, while the EPSS score of less than 1 % suggests that active exploitation is currently uncommon or not yet widespread. The vulnerability is not listed in the CISA KEV catalog, providing no evidence of known active attacks. Because the flaw requires an attacker to be authorized on the network and able to reach the NFS service, it is a network‑based privilege‑elevation vulnerability that could be abused by authenticated users with sufficient access rights.
OpenCVE Enrichment