Microsoft Windows 10 Version 22H2 vulnerabilities
2,407 known vulnerabilities affecting microsoft/windows_10_version_22h2.
Total CVEs
2,407
CISA KEV
79
actively exploited
Public exploits
52
Exploited in wild
96
Severity breakdown
CRITICAL63HIGH1710MEDIUM623LOW11
Vulnerabilities
Page 11 of 121
CVE-2024-43452P3HIGHCVSS 7.5≥ 10.0.19045.0, < 10.0.19045.51312024-11-12
CVE-2024-43452 [HIGH] CWE-367 CVE-2024-43452: Windows Registry Elevation of Privilege Vulnerability
Windows Registry Elevation of Privilege Vulnerability
nvd
CVE-2026-42904P2CRITICALCVSS 9.6≥ 10.0.19045.0, < 10.0.19045.74172026-06-09
CVE-2026-42904 [CRITICAL] CWE-122 CVE-2026-42904: Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges o
Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.
nvd
CVE-2025-50171P2CRITICALCVSS 9.1≥ 10.0.19045.0, < 10.0.19045.62162025-08-12
CVE-2025-50171 [CRITICAL] CWE-862 CVE-2025-50171: Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing o
Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-42985P3HIGHCVSS 8.8≥ 10.0.19045.0, < 10.0.19045.74172026-06-09
CVE-2026-42985 [HIGH] CWE-416 CVE-2026-42985: Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-50505P3HIGHCVSS 8.8≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-50505 [HIGH] CWE-416 CVE-2026-50505: Use after free in Windows Message Queuing allows an authorized attacker to execute code over a netwo
Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.
nvd
CVE-2024-30078P3HIGHCVSS 8.8≥ 10.0.19045.0, < 10.0.19045.45292024-06-11
CVE-2024-30078 [HIGH] CWE-20 CVE-2024-30078: Windows Wi-Fi Driver Remote Code Execution Vulnerability
Windows Wi-Fi Driver Remote Code Execution Vulnerability
nvd
CVE-2025-33070P3HIGHCVSS 8.1≥ 10.0.19045.0, < 10.0.19045.59652025-06-10
CVE-2025-33070 [HIGH] CWE-908 CVE-2025-33070: Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privile
Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2024-38240P3CRITICALCVSS 9.8≥ 10.0.19045.0, < 10.0.19045.48942024-09-10
CVE-2024-38240 [CRITICAL] CWE-125 CVE-2024-38240: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
nvd
CVE-2026-49798P3CRITICALCVSS 9.3≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-49798 [CRITICAL] CWE-416 CVE-2026-49798: Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2025-26645P3HIGHCVSS 8.8≥ 10.0.19045.0, < 10.0.19045.56082025-03-11
CVE-2025-26645 [HIGH] CWE-23 CVE-2025-26645: Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code ove
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-49164P3CRITICALCVSS 9.8≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-49164 [CRITICAL] CWE-122 CVE-2026-49164: Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to ex
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-53722P3HIGHCVSS 7.5≥ 10.0.19045.0, < 10.0.19045.62162025-08-12
CVE-2025-53722 [HIGH] CWE-400 CVE-2025-53722: Uncontrolled resource consumption in Windows Remote Desktop Services allows an unauthorized attacker
Uncontrolled resource consumption in Windows Remote Desktop Services allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50380P3CRITICALCVSS 9.6≥ 10.0.19045.0, < 10.0.19045.75482026-07-14
CVE-2026-50380 [CRITICAL] CWE-122 CVE-2026-50380: Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a ne
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-20678P3HIGHCVSS 8.8≥ 10.0.19045.0, < 10.0.19045.42912024-04-09
CVE-2024-20678 [HIGH] CWE-843 CVE-2024-20678: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2023-38148P3HIGHCVSS 8.8≥ 10.0.19045.0, < 10.0.19045.34482023-09-12
CVE-2023-38148 [HIGH] CWE-121 CVE-2023-38148: Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
nvd
CVE-2023-36423P3HIGHCVSS 8.8≥ 10.0.19045.0, < 10.0.19045.36932023-11-14
CVE-2023-36423 [HIGH] CWE-122 CVE-2023-36423: Microsoft Remote Registry Service Remote Code Execution Vulnerability
Microsoft Remote Registry Service Remote Code Execution Vulnerability
nvd
CVE-2026-20840P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.68092026-01-13
CVE-2026-20840 [HIGH] CWE-122 CVE-2026-20840: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2025-59295P3HIGHCVSS 8.8≥ 10.0.19045.0, < 10.0.19045.64562025-10-14
CVE-2025-59295 [HIGH] CWE-122 CVE-2025-59295: Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over
Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-24051P3HIGHCVSS 8.8≥ 10.0.19045.0, < 10.0.19045.56082025-03-11
CVE-2025-24051 [HIGH] CWE-122 CVE-2025-24051: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2023-35641P3HIGHCVSS 8.8≥ 10.0.19045.0, < 10.0.19045.38032023-12-12
CVE-2023-35641 [HIGH] CWE-682 CVE-2023-35641: Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
nvd