cbcvebase.

Microsoft Windows 10 Version 22H2 vulnerabilities

2,003 known vulnerabilities affecting microsoft/windows_10_version_22h2.

Total CVEs
2,003
CISA KEV
79
actively exploited
Public exploits
34
Exploited in wild
51
Severity breakdown
CRITICAL44HIGH1420MEDIUM531LOW8

Vulnerabilities

Page 25 of 101
CVE-2025-54092HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.63322025-09-09
CVE-2025-54092 [HIGH] CWE-362 CVE-2025-54092: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55224HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.63322025-09-09
CVE-2025-55224 [HIGH] CWE-362 CVE-2025-55224: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
nvd
CVE-2025-54111HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.63322025-09-09
CVE-2025-54111 [HIGH] CWE-416 CVE-2025-54111: Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate pr Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55228HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.63322025-09-09
CVE-2025-55228 [HIGH] CWE-362 CVE-2025-55228: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
nvd
CVE-2025-54112HIGHCVSS 7.0≥ 10.0.19045.0, < 10.0.19045.63322025-09-09
CVE-2025-54112 [HIGH] CWE-416 CVE-2025-54112: Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges l Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54115HIGHCVSS 7.0≥ 10.0.19045.0, < 10.0.19045.63322025-09-09
CVE-2025-54115 [HIGH] CWE-362 CVE-2025-54115: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53804MEDIUMCVSS 5.5≥ 10.0.19045.0, < 10.0.19045.63322025-09-09
CVE-2025-53804 [MEDIUM] CWE-200 CVE-2025-53804: Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized at Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2025-53810MEDIUMCVSS 6.7≥ 10.0.19045.0, < 10.0.19045.63322025-09-09
CVE-2025-53810 [MEDIUM] CWE-843 CVE-2025-53810: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53799MEDIUMCVSS 5.5≥ 10.0.19045.0, < 10.0.19045.63322025-09-09
CVE-2025-53799 [MEDIUM] CWE-908 CVE-2025-53799: Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclo Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.
nvd
CVE-2025-54915MEDIUMCVSS 6.7≥ 10.0.19045.0, < 10.0.19045.63322025-09-09
CVE-2025-54915 [MEDIUM] CWE-843 CVE-2025-54915: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54109MEDIUMCVSS 6.7≥ 10.0.19045.0, < 10.0.19045.63322025-09-09
CVE-2025-54109 [MEDIUM] CWE-843 CVE-2025-54109: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54107MEDIUMCVSS 4.3≥ 10.0.19045.0, < 10.0.19045.63322025-09-09
CVE-2025-54107 [MEDIUM] CWE-41 CVE-2025-54107: Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to b Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2025-54104MEDIUMCVSS 6.7≥ 10.0.19045.0, < 10.0.19045.63322025-09-09
CVE-2025-54104 [MEDIUM] CWE-843 CVE-2025-54104: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54917MEDIUMCVSS 4.3≥ 10.0.19045.0, < 10.0.19045.63322025-09-09
CVE-2025-54917 [MEDIUM] CWE-693 CVE-2025-54917: Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a sec Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2025-54101MEDIUMCVSS 4.8≥ 10.0.19045.0, < 10.0.19045.63322025-09-09
CVE-2025-54101 [MEDIUM] CWE-416 CVE-2025-54101: Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network. Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network.
nvd
CVE-2025-55226MEDIUMCVSS 6.7≥ 10.0.19045.0, < 10.0.19045.63322025-09-09
CVE-2025-55226 [MEDIUM] CWE-362 CVE-2025-55226: Concurrent execution using shared resource with improper synchronization ('race condition') in Graph Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to execute code locally.
nvd
CVE-2025-53803MEDIUMCVSS 5.5≥ 10.0.19045.0, < 10.0.19045.63322025-09-09
CVE-2025-53803 [MEDIUM] CWE-209 CVE-2025-53803: Generation of error message containing sensitive information in Windows Kernel allows an authorized Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2025-53808MEDIUMCVSS 6.7≥ 10.0.19045.0, < 10.0.19045.63322025-09-09
CVE-2025-53808 [MEDIUM] CWE-843 CVE-2025-53808: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54094MEDIUMCVSS 6.7≥ 10.0.19045.0, < 10.0.19045.63322025-09-09
CVE-2025-54094 [MEDIUM] CWE-843 CVE-2025-54094: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55230HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.60932025-08-21
CVE-2025-55230 [HIGH] CWE-822 CVE-2025-55230: Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to eleva Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally.
nvd