GPU VulnDB

Database/Kernel, userspace & hypervisor

Windows Server Services for NFS: use-after-free in the ONCRPC XDR driver gives local code execution

CVSS 7.0CVE-2026-70585Kernel, userspace & hypervisorcurated

Impact

A use-after-free in the ONCRPC XDR driver that backs the Services for NFS role lets an already-authorized local user execute code, and because the flaw is in a kernel-mode driver the resulting code runs with kernel privilege. This matters only on Windows Server nodes that actually have the Services for NFS role installed - typically file gateways bridging Linux GPU nodes to Windows storage, not the accelerator hosts themselves. Where it is installed, one local account on the box becomes full control of a machine that exports shared datasets. Microsoft rates it 7.0 with high attack complexity, so it is a real escalation path rather than a turnkey one.

Who can reach it

A local user already authenticated on a Windows Server 2012, 2012 R2, 2016 or 2019 host with the Services for NFS role installed. No user interaction, but the record marks attack complexity high. Not reachable over the network.

What to do

Install the September 2026 Windows Server cumulative update covering this CVE; the MSRC entry carries the per-SKU KB numbers. Patching a kernel driver on Windows requires a reboot, so plan a per-node maintenance window and move NFS exports to a peer first. If the Services for NFS role is not needed on a given server, removing it eliminates the exposure without waiting for the patch window.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.