CVE-2022-26937

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published May 10, 2022
Updated: Jan 2, 2025

Summary

CVE-2022-26937 is a remote code execution vulnerability affecting Windows Network File System (NFS). This issue allows an unauthenticated attacker to send a specially crafted packet to a targeted NFS server, leading to arbitrary code execution on the system. Successful exploitation of this vulnerability could result in the attacker gaining full control over the affected Windows server. Organizations using NFS should promptly apply the available Microsoft security patch to mitigate this risk. Failure to do so may result in serious security consequences.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Windows Server 2022
  • Microsoft Windows Server 2012
  • Microsoft Windows Server 2008
  • Microsoft Windows Server 2016
  • Microsoft Windows Server 2019

Affected Vendors

  • Microsoft