Description
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution on the Windows NFS ONCRPC XDR Driver
Action: Immediate Patch
AI Analysis

Impact

A use‑after‑free flaw in the Windows Services for NFS ONCRPC XDR Driver allows an attacker to execute arbitrary code. The vulnerability is classified as CWE‑416. If exploited, the attacker could gain the privileges of the service process, potentially compromising the entire host and all data stored on it. The flaw is triggered by the driver freeing an object and then accessing it again, a classic memory corruption scenario that leads to runtime code execution.

Affected Systems

The flaw affects Microsoft Windows Server versions 2012 through 2025, including both standard and Server Core installations. The affected products are Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025. All builds of these operating systems that include the ONCRPC XDR Driver are susceptible as listed in the CNA data.

Risk and Exploitability

With a CVSS score of 9.8, the vulnerability is classified as Critical. No EPSS score is provided, so the exact exploitation probability is unknown at this time, but the lack of a KEV listing does not mitigate the fact that the flaw permits remote execution without authentication. The likely attack vector is a network‑based exploit where an unauthenticated attacker sends specially crafted NFS packets to the vulnerable driver, triggering the memory corruption and achieving code execution.

Generated by OpenCVE AI on September 9, 2026 at 02:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft cumulative update that addresses CVE-2026-78445 – see the MSRC advisory for the specific update package.
  • If an immediate patch cannot be applied, deny inbound network access to the NFS service or disable the Windows NFS service entirely using the local services console or group policy.
  • Configure logging and monitor for anomalous network traffic or failed service requests that could indicate an ongoing exploit attempt.

Generated by OpenCVE AI on September 9, 2026 at 02:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*

Thu, 10 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows Server 2012 (server Core Installation)
Microsoft windows Server 2012 R2
Microsoft windows Server 2012 R2 (server Core Installation)
Microsoft windows Server 2016 (server Core Installation)
Microsoft windows Server 2019 (server Core Installation)
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows Server 2012 (server Core Installation)
Microsoft windows Server 2012 R2
Microsoft windows Server 2012 R2 (server Core Installation)
Microsoft windows Server 2016 (server Core Installation)
Microsoft windows Server 2019 (server Core Installation)
Microsoft windows Server 2025 (server Core Installation)

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.
Title Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows Server 2012 Windows Server 2012 (server Core Installation) Windows Server 2012 R2 Windows Server 2012 R2 Windows Server 2012 R2 (server Core Installation) Windows Server 2016 Windows Server 2016 (server Core Installation) Windows Server 2019 Windows Server 2019 (server Core Installation) Windows Server 2022 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:38:07.211Z

Reserved: 2026-08-24T16:21:50.286Z

Link: CVE-2026-78445

cve-icon Vulnrichment

Updated: 2026-09-09T09:53:36.263Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:42.263

Modified: 2026-09-24T23:19:05.270

Link: CVE-2026-78445

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T00:15:13Z

Weaknesses