CVE-2026-70585 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
CVSS 7
IMPORTANT
Critical - Same Day Deployment
“A successful race-condition attack could turn limited local access into full code execution, putting the confidentiality, integrity, and availability of critical Windows servers at risk.”
CVE-2026-70585 is a critical use-after-free vulnerability in the Windows Services for NFS ONCRPC XDR Driver. An authorized attacker with low privileges could exploit the flaw locally to execute code. Successful exploitation requires winning a race condition, making the attack complexity high, but no user interaction is required.
Key Details
- Attack Vector
- Local
- Attack Complexity
- High
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-416
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.