Impact
A heap-based buffer overflow exists in the Windows Network File System (NFS) component. An attacker who can already authenticate to the system and access the NFS service can exercise the overflow to gain code execution, thereby elevating their privileges to the system local administrator level. The weakness corresponds to CWE-122 and involves a data–value overflow described by CWE-197. The impact is the loss of integrity and confidentiality for all files and processes under the compromised account, and potentially availability issues if the attacker disrupts the NFS service.
Affected Systems
Microsoft Windows operating systems from Windows 10 version 1607 through Windows 11 version 26H1 and Windows Server family from 2012 to 2025, including both standard and server-core installations, are affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. The EPSS score, less than 1 %, shows a very low likelihood of exploitation in the wild, and the issue is not currently listed in the CISA KEV catalog. The attack vector is local and requires the attacker to be authenticated on the target machine with access to the NFS service. An exploit would typically involve crafting a malicious NFS request that triggers the overflow, though no public exploit has been disclosed. The overall risk is moderate, but because the vulnerability permits elevation to local administrator rights, it should be addressed promptly.
OpenCVE Enrichment