Database/Kernel, userspace & hypervisor

Windows Server Services for NFS: use-after-free in the ONCRPC XDR driver gives local code execution
Impact
A use-after-free in the ONCRPC XDR driver that backs the Services for NFS role lets an already-authorized local user execute code, and because the flaw is in a kernel-mode driver the resulting code runs with kernel privilege. This matters only on Windows Server nodes that actually have the Services for NFS role installed - typically file gateways bridging Linux GPU nodes to Windows storage, not the accelerator hosts themselves. Where it is installed, one local account on the box becomes full control of a machine that exports shared datasets. Microsoft rates it 7.0 with high attack complexity, so it is a real escalation path rather than a turnkey one.
Who can reach it
A local user already authenticated on a Windows Server 2012, 2012 R2, 2016 or 2019 host with the Services for NFS role installed. No user interaction, but the record marks attack complexity high. Not reachable over the network.
What to do
Install the September 2026 Windows Server cumulative update covering this CVE; the MSRC entry carries the per-SKU KB numbers. Patching a kernel driver on Windows requires a reboot, so plan a per-node maintenance window and move NFS exports to a peer first. If the Services for NFS role is not needed on a given server, removing it eliminates the exposure without waiting for the patch window.
References
Related entries
- Xen through 4.12.x - passed-through PCI devices left able to DMA into host memory after being handed to an untrustedCVE-2019-18424 · Xen through 4.12.x - passed-through PCI devices left able to DMA into host memory after being handed to an untrusted…Medium
- Xen on AMD-Vi (AMD IOMMU) - ACPI IVMD unity-map page permissions: Xen honours ACPI-described IOMMU unity mappings butCVE-2021-28694 · Xen on AMD-Vi (AMD IOMMU) - ACPI IVMD unity-map page permissionsMedium
- Xen on AMD-Vi - IOMMU page mapping permissions: Second of the XSA-378 IOMMU page-mapping issues on AMD-Vi. IncorrectCVE-2021-28695 · Xen on AMD-Vi - IOMMU page mapping permissionsMedium
- Xen on AMD-Vi - IOMMU page mapping permissions: Third of the XSA-378 AMD-Vi mapping issues. Same practical consequenceCVE-2021-28696 · Xen on AMD-Vi - IOMMU page mapping permissionsMedium
- Linux kernel (arch/x86/kvm): A failed RSM leaves the vCPU's SMM flag and the MMU role out of sync, so KVM resolves aCVE-2021-47230 · Linux kernel (arch/x86/kvm)Medium
- VMware ESXi: AD-integrated ESXi grants full host admin to any member of a re-created "ESX Admins" groupCVE-2024-37085 · VMware ESXiMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.