CVE-2022-30136CriticalCVSS 9.8

Windows Network File System Remote Code Execution Vulnerability

Published
June 14, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit this vulnerability? This vulnerability could be exploited over the network by making an unauthenticated, specially crafted call to a Network File System (NFS) service to trigger a Remote Code Execution (RCE).

🎯 Affected products8

  • Windows Server 2012
  • Windows Server 2012 (Server Core installation)
  • Windows Server 2012 R2
  • Windows Server 2012 R2 (Server Core installation)
  • Windows Server 2016
  • Windows Server 2016 (Server Core installation)
  • Windows Server 2019
  • Windows Server 2019 (Server Core installation)

✅ Remediation

KB5014692 (Security Update) — fixed build 10.0.17763.3046 KB5014702 (Security Update) — fixed build 10.0.14393.5192 KB5014747 (Monthly Rollup) — fixed build 6.2.9200.23736 KB5014741 (Security Only) — fixed build 6.2.9200.23736 KB5014738 (Monthly Rollup) — fixed build 6.3.9600.20402 KB5014746 (Security Only) — fixed build 6.3.9600.20402

🔗 References (12)