CVE-2022-30136

CVSS 2.0 Score 10 of 10 (high)

Details

Published Jun 15, 2022
Updated: Jan 2, 2025

Summary

CVE-2022-30136 is a recently disclosed remote code execution vulnerability affecting the Windows Network File System (NFS). This issue allows an unauthenticated attacker to execute arbitrary code on a targeted system by sending maliciously crafted packets to the NFS server. Successful exploitation could result in the attacker gaining full control of the affected system, potentially leading to data theft, unauthorized access, or further attacks. It is strongly recommended that affected organizations apply the available Microsoft security patch as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2012
  • Microsoft Windows Server 2016
  • Microsoft Windows Server 2019
  • Microsoft Windows Server 2012 R2

Affected Vendors

  • Microsoft