Vulnerability record · CVE-2022-34715 · published 9 August 2022
CVE-2022-34715: Windows Network File System remote code execution
Microsoft · Windows Server 2022
CVE-2022-34715 is a remote code execution flaw in the Windows Network File System (NFS) service, rated critical with a CVSS 3.1 base score of 9.8. The record gives only a one-line description and no root-cause detail, so the exact vulnerable code path is not documented here. Because NFS is a network-facing service, an unauthenticated attacker reaching it could execute code with high impact to confidentiality, integrity and availability.
Description
Windows Network File System Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network-reachable, unauthenticated remote code execution and a very high EPSS score make this a top remediation priority despite the thin description.
What it is
CVE-2022-34715 is a remote code execution flaw in the Windows Network File System (NFS) service, rated critical with a CVSS 3.1 base score of 9.8. The record gives only a one-line description and no root-cause detail, so the exact vulnerable code path is not documented here. Because NFS is a network-facing service, an unauthenticated attacker reaching it could execute code with high impact to confidentiality, integrity and availability.
Impact
An attacker who successfully exploits the flaw gains remote code execution on the target Windows server, giving full control of the affected host. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
The vector AV:N/AC:L/PR:N/UI:N indicates the flaw is reachable over the network with no authentication and no user interaction. The affected component is the Windows NFS service, so exposure depends on that service being enabled and reachable.
Exploitation
The record shows no CISA KEV listing and no reference tags indicating public exploit code, but EPSS is very high at 0.804 (99.6th percentile), suggesting elevated likelihood of attempted exploitation. No confirmed in-the-wild exploitation is stated in the supplied data.
What to do
- Apply the Microsoft security update for CVE-2022-34715 as the first action.
- If NFS is not required, disable or uninstall the Windows NFS service and its Server for NFS role.
- Restrict network access to NFS ports (TCP/UDP 2049 and related RPC ports) to trusted hosts only, using host firewall or network segmentation.
- Monitor Microsoft advisories for any follow-up guidance or revised patches for this CVE.
Detection
- Review Windows event logs and NFS service logs for unexpected crashes, restarts or anomalous RPC/NFS requests on servers running the NFS role.
- Hunt for unusual inbound connections to NFS and RPC ports from untrusted or external source addresses.
- Monitor for suspicious child processes spawned by the NFS service or unexpected process creation on NFS-enabled hosts.
- Inventory which servers have the NFS role enabled to confirm patch coverage and reduce exposed surface.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-34715 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-34715), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.