Impact
A use-after-free flaw in the Windows Services for NFS ONCRPC XDR Driver enables an unauthorized attacker to execute code on the target system. The vulnerability is a classic memory corruption bug (CWE-416) that is triggered when the driver attempts to use an object that has already been freed. Successful exploitation gives the attacker arbitrary code execution with the privileges of the service process, potentially allowing full control of the affected system.
Affected Systems
The flaw affects Microsoft Windows Server products from 2012 through 2025, including both standard and Server Core installations. In particular, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025 are listed as impacted versions.
Risk and Exploitability
The CVSS score of 9.8 marks this as critical. The EPSS score is 1%, the flaw is not yet listed in CISA’s KEV catalog, suggesting limited public exploitation data. The likely attack vector is network-based: a remote host can trigger the flaw by interacting with the vulnerable NFS/ONCRPC XDR service, leading to remote code execution on the affected Windows Server.
OpenCVE Enrichment