CVE-2022-26937 is a critical Remote Code Execution vulnerability affecting multiple versions of Microsoft Windows Server, specifically within the Network File System (NFS). With a CVSS score of 9.8, this vulnerability allows an unauthenticated attacker to execute arbitrary code remotely with high impact on confidentiality, integrity, and availability, requiring no user interaction. While not listed on CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, media coverage and community discussion indicate significant awareness, with some reports suggesting it was actively exploited as a zero-day.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
20h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server:20h2:*:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x86:* | ||
sp2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:sp2:*:*:*:*:*:x64:* | ||
sp2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:sp2:*:*:*:*:*:x86:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.