Impact
This vulnerability is a flaw in the Windows Services for NFS ONCRPC XDR Driver that allows an attacker to obtain sensitive system information that should be restricted to a privileged control sphere. The flaw can be triggered by an unauthorized attacker who can send specially crafted requests to the driver from a remote network, resulting in the disclosure of potentially critical configuration and system data. The impact is the leakage of sensitive information, which can be used to further compromise the host or aid in planning additional attacks.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including their server core variants. All affected systems run the Windows Services for NFS ONCRPC XDR Driver that contains the disclosed weakness.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity of information disclosure, with the EPSS score not available and the vulnerability not listed in CISA's Known Exploit Vulnerabilities catalog. The likely attack vector is remote network activity, where an attacker able to reach the NFS service can send malicious packets to the driver. Because the flaw exposes system data without authentication or privilege escalation, the threat is that attackers with network access can gather detailed configuration information that could enable further attacks. The lack of a known exploit in the public domain yet suggests that the immediate risk is moderate, but the potential for widespread exposure warrants swift action.
OpenCVE Enrichment