CVE-2022-34715HighCVSS 9.8

Windows Network File System Remote Code Execution Vulnerability

Published
August 9, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit this vulnerability? This vulnerability could be exploited over the network by making an unauthenticated, specially crafted call to a Network File System (NFS) service to trigger a Remote Code Execution (RCE).

What version of Network File System (NFS) is affected by this vulnerability? Servers that have Network File System version 4.0 (NFS 4.0) installed are affected by this vulnerability.

I am running a supported version of Windows Server. Is my system vulnerable to this issue? This vulnerability is only exploitable for systems that have the NFS role enabled. See NFS Overview for more information on this feature. More information on installing or uninstalling Roles or Role Services is available here.

🎯 Affected products2

  • Windows Server 2022
  • Windows Server 2022 (Server Core installation)

✅ Remediation

KB5016627 (Security Update) — fixed build 10.0.20348.887

🔗 References (3)