Impact
The vulnerability is a heap‑based buffer overflow in the Windows Services for NFS ONCRPC XDR Driver. It allows an attacker who already has authorization on the machine to execute arbitrary code with elevated privileges, potentially achieving SYSTEM level access. The weakness can be classified as CWE‑122 and results in a change of privilege state rather than denial of service or confidentiality loss.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012, 2012 (Server Core), 2012 R2, 2012 R2 (Server Core), Server 2016, Server 2016 (Server Core), Server 2019, Server 2019 (Server Core), Server 2022, Server 2025, Server 2025 (Server Core). All listed operating systems contain the vulnerable NFS driver implementation.
Risk and Exploitability
The CVSS score of 7.8 indicates serious potential for local privilege escalation. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, there is no publicly known exploitation data, but the lack of mitigation artifacts does not eliminate the risk. The likely attack vector requires a local attacker with access to submit specially crafted requests to the ONCRPC XDR service; successful exploitation would allow execution as SYSTEM and full control of the affected machine.
OpenCVE Enrichment