CVE-2021-26432: Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20094Patch KB5005106 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20094Patch KB5005076 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4583Patch KB5005043 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23435Patch KB5005094 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19022Patch KB5005040 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.1165Patch KB5005033 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19041.1165Patch KB5005033 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.1165Patch KB5005033 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1734Patch KB5005031 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.2114Patch KB5005030
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26432?
CVE-2021-26432 has a critical severity rating due to the potential for remote code execution.
How do I fix CVE-2021-26432?
To remediate CVE-2021-26432, ensure that you apply the latest security updates provided by Microsoft for affected Windows versions.
Which systems are affected by CVE-2021-26432?
CVE-2021-26432 affects multiple versions of Microsoft Windows including Windows 10, Windows 8.1, and Windows Server editions.
What impact does CVE-2021-26432 have on affected systems?
CVE-2021-26432 allows an attacker to execute arbitrary code on affected systems, leading to potential system compromise.
Is there a workaround for CVE-2021-26432?
While the recommended action is to apply updates, disabling the ONCRPC service could serve as a temporary workaround for CVE-2021-26432.