{
  "id": 12151688,
  "title": "CVE-2026-70585: A Use-After-Free in the Windows NFS Client Stack",
  "url": "https://urgent.news/2026/10/05/cve-2026-70585-a-use-after-free-in-the-windows-nfs-client-stack",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-05T12:40:29.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/jeffreyciend/cve-2026-70585-a-use-after-free-in-the-windows-nfs-client-stack-15c3"
  },
  "original_language": "en",
  "account": "In September 2026, the US National Vulnerability Database (NVD) disclosed a security flaw affecting Windows Services for NFS, known as CVE-2026-70585. This vulnerability is a use-after-free issue within the ONCRPC XDR driver, a parser responsible for handling external data representation in the Windows kernel. Although the Common Vulnerability Scoring System (CVSS) assigned it a relatively low score of 7.0, the implications are significant.\n\nThe NVD explains that an attacker, acting through the NFS server they control, could exploit this flaw to execute arbitrary code on a compromised Windows system. Despite the description stating that the impact is local, the reality is that an attacker could manipulate the NFS server to influence the client's parsing process, ultimately leading to a serious security breach.\n\nNFS shares can be mounted from various sources, including internal servers, NAS appliances, or even hostile entities. This means that any system with the NFS client feature installed is at risk. To mitigate this vulnerability, Microsoft recommends applying the September 2026 security updates to all Windows hosts with the NFS client feature enabled. It is also advised to assess whether the Windows-to-NFS path is necessary, as removing this protocol could eliminate potential attack vectors.",
  "summary": "CVE-2026-70585: A Use-After-Free in the Windows NFS Client Stack Windows can mount NFS shares as a client, and that capability pulls a remote procedure call parser into the kernel's network path. CVE-2026-70585 is a use-after-free in that parser, and it is a good example of a low CVSS score attached to a high-consequence code path. What the record says NVD describes CVE-2026-70585 as a…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}