Impact
A use‑after‑free flaw in the Windows Services for NFS ONCRPC XDR Driver allows an attacker to execute arbitrary code. The vulnerability is classified as CWE‑416. If exploited, the attacker could gain the privileges of the service process, potentially compromising the entire host and all data stored on it. The flaw is triggered by the driver freeing an object and then accessing it again, a classic memory corruption scenario that leads to runtime code execution.
Affected Systems
The flaw affects Microsoft Windows Server versions 2012 through 2025, including both standard and Server Core installations. The affected products are Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025. All builds of these operating systems that include the ONCRPC XDR Driver are susceptible as listed in the CNA data.
Risk and Exploitability
With a CVSS score of 9.8, the vulnerability is classified as Critical. No EPSS score is provided, so the exact exploitation probability is unknown at this time, but the lack of a KEV listing does not mitigate the fact that the flaw permits remote execution without authentication. The likely attack vector is a network‑based exploit where an unauthenticated attacker sends specially crafted NFS packets to the vulnerable driver, triggering the memory corruption and achieving code execution.
OpenCVE Enrichment