First published: Tue Apr 05 2022(Updated: )
Windows Network File System Remote Code Execution Vulnerability
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Server 2012 R2 | ||
Microsoft Windows Server | =20H2 | |
Microsoft Windows Server 2012 R2 | ||
Microsoft Windows RT | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows 8.1 | ||
Microsoft Windows 8.1 | ||
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2019 | ||
Windows 11 | =21H2 | |
Windows 11 | =21H2 | |
Microsoft Windows Server 2022 | ||
Microsoft Windows Server 2022 | ||
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | ||
Windows 10 | =20H2 | |
Windows 10 | =20H2 | |
Windows 10 | =20H2 | |
Windows 10 | =1809 | |
Windows 10 | =1809 | |
Windows 10 | =1809 | |
Windows 10 | =1607 | |
Windows 10 | =1607 | |
Windows 10 | =21H1 | |
Windows 10 | =21H1 | |
Windows 10 | =21H1 | |
Windows 10 | =21H2 | |
Windows 10 | =21H2 | |
Windows 10 | =21H2 | |
Windows 10 | =1909 | |
Windows 10 | =1909 | |
Windows 10 | =1909 | |
Windows 10 | ||
Windows 10 | ||
Windows 10 | ||
Windows 10 | =20h2 | |
Windows 10 | =21h1 | |
Windows 10 | =21h2 | |
Windows 10 | =1607 | |
Windows 10 | =1809 | |
Windows 10 | =1909 | |
Windows 11 | ||
Windows 11 | ||
Microsoft Windows | ||
Microsoft Windows RT | ||
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | =20h2 | |
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2022 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24497 has a CVSS score indicating a critical severity level.
To fix CVE-2022-24497, apply the latest security updates provided by Microsoft for the affected Windows versions.
CVE-2022-24497 affects multiple versions of Windows, including Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022.
Exploitation of CVE-2022-24497 could allow an attacker to execute arbitrary code on the affected system remotely.
While applying patches is recommended, disabling certain features or restricting network access may serve as temporary workarounds for CVE-2022-24497.