Vulnerability record · CVE-2022-34718 · published 13 September 2022
CVE-2022-34718: Windows TCP/IP stack remote code execution
Microsoft · Windows 10
CVE-2022-34718 is a remote code execution flaw in the Windows TCP/IP implementation affecting a broad range of Windows client and server versions. It is network-reachable with no privileges or user interaction required, and the record gives no root-cause detail beyond the generic description.
Description
Windows TCP/IP Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no privileges or interaction, and high EPSS make this a top patching priority despite no confirmed exploitation.
What it is
CVE-2022-34718 is a remote code execution flaw in the Windows TCP/IP implementation affecting a broad range of Windows client and server versions. It is network-reachable with no privileges or user interaction required, and the record gives no root-cause detail beyond the generic description.
Impact
A successful attacker can execute arbitrary code on the target host, potentially at system level, giving full control of the affected machine.
Attack surface
Reachable over the network via the TCP/IP stack (CVSS AV:N, PR:N, UI:N), so no authentication or user action is needed. The record does not specify which protocol path or packet type triggers the flaw.
Exploitation
Not listed in CISA KEV and no reference tags indicate in-the-wild exploitation, but EPSS is high at roughly 0.54 (99th percentile), suggesting elevated likelihood of attempted exploitation.
What to do
- Apply the Microsoft security update for CVE-2022-34718 as the first action.
- Inventory all listed Windows client and server versions and prioritize internet-facing and unpatched hosts.
- Restrict unnecessary exposure of TCP/IP services at the network edge and segment critical systems.
- Monitor Microsoft advisories for any updated guidance or known-exploitation status.
Detection
- Monitor for unexpected crashes or restarts of the Windows TCP/IP stack or related services.
- Alert on anomalous outbound or inbound network traffic patterns to hosts running affected Windows versions.
- Correlate host telemetry for suspicious process creation or code execution following network activity on patched-versus-unpatched systems.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-34718 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-34718), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.