Impact
An out‑of‑bounds read in the Windows Services for NFS ONCRPC XDR driver can be triggered by an unauthorized attacker, causing the driver process to crash and resulting in a denial of service. The vulnerability does not directly compromise confidentiality or integrity; however, repeated exploitation can make the affected services unavailable to legitimate users.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, including Server Core installations. The vulnerability is present in the NFS ONCRPC XDR driver component bundled with these operating system releases.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact and moderate exploitation complexity. EPSS is not available, and the vulnerability is not listed in CISA KEV, so the likelihood of widespread exploitation is uncertain. The likely attack vector is network‑based, as the denial of service can be triggered by requests over the network to the vulnerable service. Vulnerability is exploitable by an unauthorized attacker with network access to the affected machine, and may not require prior authentication.
OpenCVE Enrichment