First published: Thu Aug 12 2021(Updated: )
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 10 | ||
Microsoft Windows 10 | =20h2 | |
Microsoft Windows 10 | =21h1 | |
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =1909 | |
Microsoft Windows 10 | =2004 | |
Microsoft Windows 8.1 | ||
Microsoft Windows RT | ||
Microsoft Windows Server 2012 x64 | ||
Microsoft Windows Server 2012 x64 | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | =20h2 | |
Microsoft Windows Server 2016 | =2004 | |
Microsoft Windows Server 2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26432 has a critical severity rating due to the potential for remote code execution.
To remediate CVE-2021-26432, ensure that you apply the latest security updates provided by Microsoft for affected Windows versions.
CVE-2021-26432 affects multiple versions of Microsoft Windows including Windows 10, Windows 8.1, and Windows Server editions.
CVE-2021-26432 allows an attacker to execute arbitrary code on affected systems, leading to potential system compromise.
While the recommended action is to apply updates, disabling the ONCRPC service could serve as a temporary workaround for CVE-2021-26432.