CVE-2026-70585 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability

CVSS 7 IMPORTANT Critical - Same Day Deployment

“A successful race-condition attack could turn limited local access into full code execution, putting the confidentiality, integrity, and availability of critical Windows servers at risk.”

CVE-2026-70585 is a critical use-after-free vulnerability in the Windows Services for NFS ONCRPC XDR Driver. An authorized attacker with low privileges could exploit the flaw locally to execute code. Successful exploitation requires winning a race condition, making the attack complexity high, but no user interaction is required.

Key Details

Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-416
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.