Use-after-free in Windows Server - CVE-2026-78445
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Windows Services for NFS ONCRPC XDR Driver when processing a specially crafted call to a Network File System service. A remote attacker can make a specially crafted call to a Network File System service to execute arbitrary code.