Microsoft Windows 10 Version 22H2 vulnerabilities
2,407 known vulnerabilities affecting microsoft/windows_10_version_22h2.
Total CVEs
2,407
CISA KEV
79
actively exploited
Public exploits
52
Exploited in wild
97
Severity breakdown
CRITICAL63HIGH1710MEDIUM623LOW11
Vulnerabilities
Page 47 of 121
CVE-2023-21812P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.26042023-02-14
CVE-2023-21812 [HIGH] CWE-122 CVE-2023-21812: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-30035P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.44122024-05-14
CVE-2024-30035 [HIGH] CWE-416 CVE-2024-30035: Windows DWM Core Library Elevation of Privilege Vulnerability
Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2026-35422P3MEDIUMCVSS 6.5≥ 10.0.19045.0, < 10.0.19045.74172026-05-12
CVE-2026-35422 [MEDIUM] CWE-288 CVE-2026-35422: Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized atta
Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network.
nvd
CVE-2024-38147P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.47802024-08-13
CVE-2024-38147 [HIGH] CWE-416 CVE-2024-38147: Microsoft DWM Core Library Elevation of Privilege Vulnerability
Microsoft DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2023-35364P3HIGHCVSS 8.8≥ 10.0.19045.0, < 10.0.19045.32082023-07-11
CVE-2023-35364 [HIGH] CWE-190 CVE-2023-35364: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2025-26678P3HIGHCVSS 8.4≥ 10.0.19045.0, < 10.0.19045.57372025-04-08
CVE-2025-26678 [HIGH] CWE-284 CVE-2025-26678: Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attack
Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally.
nvd
CVE-2023-36425P3HIGHCVSS 8.0≥ 10.0.19045.0, < 10.0.19045.36932023-11-14
CVE-2023-36425 [HIGH] CWE-122 CVE-2023-36425: Windows Distributed File System (DFS) Remote Code Execution Vulnerability
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
nvd
CVE-2025-26641P3HIGHCVSS 7.5≥ 10.0.19045.0, < 10.0.19045.57372025-04-08
CVE-2025-26641 [HIGH] CWE-400 CVE-2025-26641: Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker
Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-48573P3HIGHCVSS 7.9≥ 10.0.19045.0, < 10.0.19045.74172026-06-09
CVE-2026-48573 [HIGH] CWE-1329 CVE-2026-48573: No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feat
No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-48576P3HIGHCVSS 7.9≥ 10.0.19045.0, < 10.0.19045.74172026-06-09
CVE-2026-48576 [HIGH] CWE-1329 CVE-2026-48576: No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feat
No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2025-32714P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.59652025-06-10
CVE-2025-32714 [HIGH] CWE-284 CVE-2025-32714: Improper access control in Windows Installer allows an authorized attacker to elevate privileges loc
Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-21389P3HIGHCVSS 7.5≥ 10.0.19045.0, < 10.0.19045.53712025-01-14
CVE-2025-21389 [HIGH] CWE-400 CVE-2025-21389: Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an un
Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-48799P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.60932025-07-08
CVE-2025-48799 [HIGH] CWE-59 CVE-2025-48799: Improper link resolution before file access ('link following') in Windows Update Service allows an a
Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-27727P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.57372025-04-08
CVE-2025-27727 [HIGH] CWE-59 CVE-2025-27727: Improper link resolution before file access ('link following') in Windows Installer allows an author
Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-38061P3HIGHCVSS 7.5≥ 10.0.19045.0, < 10.0.19045.46512024-07-09
CVE-2024-38061 [HIGH] CWE-284 CVE-2024-38061: DCOM Remote Cross-Session Activation Elevation of Privilege Vulnerability
DCOM Remote Cross-Session Activation Elevation of Privilege Vulnerability
nvd
CVE-2024-21347P3HIGHCVSS 7.5≥ 10.0.19045.0, < 10.0.19045.40462024-02-13
CVE-2024-21347 [HIGH] CWE-122 CVE-2024-21347: Microsoft ODBC Driver Remote Code Execution Vulnerability
Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2025-27731P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.57372025-04-08
CVE-2025-27731 [HIGH] CWE-20 CVE-2025-27731: Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges
Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-37982P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.50112024-10-08
CVE-2024-37982 [HIGH] CWE-822 CVE-2024-37982: Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
nvd
CVE-2025-24058P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.57372025-04-08
CVE-2025-24058 [HIGH] CWE-20 CVE-2025-24058: Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privi
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24062P3HIGHCVSS 7.8≥ 10.0.19045.0, < 10.0.19045.57372025-04-08
CVE-2025-24062 [HIGH] CWE-20 CVE-2025-24062: Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privi
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd