← Vulnerability feed

Vulnerability record · CVE-2022-34715 · published 9 August 2022

CVE-2022-34715: Windows Network File System remote code execution

Microsoft · Windows Server 2022

CVE-2022-34715 is a remote code execution flaw in the Windows Network File System (NFS) service, rated critical with a CVSS 3.1 base score of 9.8. The record gives only a one-line description and no root-cause detail, so the exact vulnerable code path is not documented here. Because NFS is a network-facing service, an unauthenticated attacker reaching it could execute code with high impact to confidentiality, integrity and availability.

9.8 CVSS 3.1 Critical EPSS 80% · top 0.4% CWE-94 · Code injection
9.8CVSS 3.1 base score
80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Windows Network File System Remote Code Execution Vulnerability

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network-reachable, unauthenticated remote code execution and a very high EPSS score make this a top remediation priority despite the thin description.

What it is

CVE-2022-34715 is a remote code execution flaw in the Windows Network File System (NFS) service, rated critical with a CVSS 3.1 base score of 9.8. The record gives only a one-line description and no root-cause detail, so the exact vulnerable code path is not documented here. Because NFS is a network-facing service, an unauthenticated attacker reaching it could execute code with high impact to confidentiality, integrity and availability.

Impact

An attacker who successfully exploits the flaw gains remote code execution on the target Windows server, giving full control of the affected host. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

The vector AV:N/AC:L/PR:N/UI:N indicates the flaw is reachable over the network with no authentication and no user interaction. The affected component is the Windows NFS service, so exposure depends on that service being enabled and reachable.

Exploitation

The record shows no CISA KEV listing and no reference tags indicating public exploit code, but EPSS is very high at 0.804 (99.6th percentile), suggesting elevated likelihood of attempted exploitation. No confirmed in-the-wild exploitation is stated in the supplied data.

What to do

  • Apply the Microsoft security update for CVE-2022-34715 as the first action.
  • If NFS is not required, disable or uninstall the Windows NFS service and its Server for NFS role.
  • Restrict network access to NFS ports (TCP/UDP 2049 and related RPC ports) to trusted hosts only, using host firewall or network segmentation.
  • Monitor Microsoft advisories for any follow-up guidance or revised patches for this CVE.

Detection

  • Review Windows event logs and NFS service logs for unexpected crashes, restarts or anomalous RPC/NFS requests on servers running the NFS role.
  • Hunt for unusual inbound connections to NFS and RPC ports from untrusted or external source addresses.
  • Monitor for suspicious child processes spawned by the NFS service or unexpected process creation on NFS-enabled hosts.
  • Inventory which servers have the NFS role enabled to confirm patch coverage and reduce exposed surface.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-34715 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-33824Double free in Windows IKE Extension enables remote code executionA double free flaw (CWE-415) exists in the Windows IKE Extension, reachable over the network by an unauthenticated attacker. Successful exploitation …KEVEPSS 1.6%analysed9.8CVE-2025-59287Microsoft WSUS deserialization flaw allows unauthenticated remote code executionWindows Server Update Service (WSUS) deserializes untrusted data, letting an unauthenticated network attacker run code on the server. The flaw is rat…KEVEPSS 100%analysed8.8CVE-2026-21510Windows Shell protection mechanism failure allows security feature bypassWindows Shell contains a protection mechanism failure (CWE-693) that lets an unauthorized attacker bypass a security feature over a network. The flaw…KEVEPSS 24%analysed8.8CVE-2026-21513Microsoft MSHTML security feature bypass on WindowsCVE-2026-21513 is a protection mechanism failure (CWE-693) in the Microsoft MSHTML Framework that lets an unauthorized attacker bypass a security fea…KEVEPSS 16%analysed8.8CVE-2025-33073Windows SMB improper access control allows privilege elevationWindows SMB contains an improper access control flaw (CWE-284) that lets an authorized attacker elevate privileges over the network. Microsoft rates …KEVEPSS 83%analysed8.8CVE-2025-33053Microsoft Windows WebDAV Internet Shortcut File Path Control RCEWindows Internet Shortcut (.url) files allow external control of a file name or path, which an unauthorized attacker can abuse to execute code over a…KEVEPSS 87%analysed8.8CVE-2024-49039Windows Task Scheduler elevation of privilege via improper authenticationCVE-2024-49039 is an elevation of privilege flaw in the Windows Task Scheduler, classified as improper authentication (CWE-287). A local attacker wit…KEVEPSS 14%analysed8.8CVE-2024-43461Windows MSHTML Platform spoofing flaw enables code executionCVE-2024-43461 is a spoofing vulnerability in the Windows MSHTML platform, the legacy rendering engine still reachable through Windows components. Th…KEVEPSS 54%analysed

Source: NIST National Vulnerability Database (record CVE-2022-34715), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.