Impact
A use‑after‑free flaw was found in the Windows Services for NFS ONCRPC XDR driver that lets an authorized local user run arbitrary code with the privileges of the driver. The vulnerability arises when memory previously freed is accessed again, allowing execution of attacker‑controlled instructions.
Affected Systems
Microsoft Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025, including both full installations and Server Core editions, are affected.
Risk and Exploitability
The CVSS base score is 7, indicating a high‑severity flaw. Portable exploitation requires a user who already has authorized access to the system, so the attack surface is limited. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation, but the high severity warrants timely patching.
OpenCVE Enrichment