Microsoft Windows 10 22H2 vulnerabilities
2,143 known vulnerabilities affecting microsoft/windows_10_22h2.
Total CVEs
2,143
CISA KEV
74
actively exploited
Public exploits
45
Exploited in wild
85
Severity breakdown
CRITICAL59HIGH1524MEDIUM551LOW9
Vulnerabilities
Page 8 of 108
CVE-2026-56194P2HIGHCVSS 8.8fixed in 10.0.19045.75482026-07-14
CVE-2026-56194 [HIGH] CWE-122 CVE-2026-56194: Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate p
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-56647P2HIGHCVSS 8.8fixed in 10.0.19045.75482026-07-14
CVE-2026-56647 [HIGH] CWE-190 CVE-2026-56647: Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized
Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2023-36910P2CRITICALCVSS 9.8fixed in 10.0.19045.33242023-08-08
CVE-2023-36910 [CRITICAL] CWE-190 CVE-2023-36910: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2023-35385P2CRITICALCVSS 9.8fixed in 10.0.19045.33242023-08-08
CVE-2023-35385 [CRITICAL] CWE-190 CVE-2023-35385: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2024-38199P2CRITICALCVSS 9.8fixed in 10.0.19045.47802024-08-13
CVE-2024-38199 [CRITICAL] CWE-416 CVE-2024-38199: Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
nvd
CVE-2023-32057P2CRITICALCVSS 9.8fixed in 10.0.19045.32082023-07-11
CVE-2023-32057 [CRITICAL] CWE-20 CVE-2023-32057: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2025-21307P2CRITICALCVSS 9.8fixed in 10.0.19045.53712025-01-14
CVE-2025-21307 [CRITICAL] CWE-416 CVE-2025-21307: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
nvd
CVE-2023-36005P3HIGHCVSS 8.1fixed in 10.0.19045.38032023-12-12
CVE-2023-36005 [HIGH] CWE-591 CVE-2023-36005: Windows Telephony Server Elevation of Privilege Vulnerability
Windows Telephony Server Elevation of Privilege Vulnerability
nvd
CVE-2026-57092P2CRITICALCVSS 9.9fixed in 10.0.19045.75482026-07-14
CVE-2026-57092 [CRITICAL] CWE-416 CVE-2026-57092: Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a networ
Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-57090P2CRITICALCVSS 9.8fixed in 10.0.19045.75482026-07-14
CVE-2026-57090 [CRITICAL] CWE-122 CVE-2026-57090: Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-49172P2CRITICALCVSS 9.8fixed in 10.0.19045.75482026-07-14
CVE-2026-49172 [CRITICAL] CWE-122 CVE-2026-49172: Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code ov
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-54995P2CRITICALCVSS 9.8fixed in 10.0.19045.75482026-07-14
CVE-2026-54995 [CRITICAL] CWE-416 CVE-2026-54995: Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to ex
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-33064P2HIGHCVSS 8.8fixed in 10.0.19045.59652025-06-10
CVE-2025-33064 [HIGH] CWE-122 CVE-2025-33064: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
nvd
CVE-2026-50666P2HIGHCVSS 8.8fixed in 10.0.19045.75482026-07-14
CVE-2026-50666 [HIGH] CWE-416 CVE-2026-50666: Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-50360P2HIGHCVSS 8.8fixed in 10.0.19045.75482026-07-14
CVE-2026-50360 [HIGH] CWE-303 CVE-2026-50360: Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized atta
Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2023-32015P2CRITICALCVSS 9.8fixed in 10.0.19045.30872023-06-14
CVE-2023-32015 [CRITICAL] CWE-20 CVE-2023-32015: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-28250P2CRITICALCVSS 9.8fixed in 10.0.19045.28462023-04-11
CVE-2023-28250 [CRITICAL] CWE-191 CVE-2023-28250: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-29363P2CRITICALCVSS 9.8fixed in 10.0.19045.30872023-06-14
CVE-2023-29363 [CRITICAL] CWE-122 CVE-2023-29363: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-32014P2CRITICALCVSS 9.8fixed in 10.0.19045.30872023-06-14
CVE-2023-32014 [CRITICAL] CWE-191 CVE-2023-32014: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-35365P2CRITICALCVSS 9.8fixed in 10.0.19045.32082023-07-11
CVE-2023-35365 [CRITICAL] CWE-20 CVE-2023-35365: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd