cbcvebase.

Microsoft Windows 11 22H2 vulnerabilities

1,432 known vulnerabilities affecting microsoft/windows_11_22h2.

Total CVEs
1,432
CISA KEV
67
actively exploited
Public exploits
43
Exploited in wild
75
Severity breakdown
CRITICAL39HIGH1001MEDIUM387LOW5

Vulnerabilities

Page 15 of 72
CVE-2024-30006P3HIGHCVSS 8.8fixed in 10.0.22621.35932024-05-14
CVE-2024-30006 [HIGH] CWE-416 CVE-2024-30006: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21349P3HIGHCVSS 8.8fixed in 10.0.22621.31552024-02-13
CVE-2024-21349 [HIGH] CWE-122 CVE-2024-21349: Microsoft ActiveX Data Objects Remote Code Execution Vulnerability Microsoft ActiveX Data Objects Remote Code Execution Vulnerability
nvd
CVE-2025-24056P3HIGHCVSS 8.8fixed in 10.0.22621.50392025-03-11
CVE-2025-24056 [HIGH] CWE-122 CVE-2025-24056: Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute co Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-43533P3HIGHCVSS 8.8fixed in 10.0.22621.43172024-10-08
CVE-2024-43533 [HIGH] CWE-416 CVE-2024-43533: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2024-43599P3HIGHCVSS 8.8fixed in 10.0.22621.43172024-10-08
CVE-2024-43599 [HIGH] CWE-416 CVE-2024-43599: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2025-21222P3HIGHCVSS 8.8fixed in 10.0.22621.51892025-04-08
CVE-2025-21222 [HIGH] CWE-122 CVE-2025-21222: Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute c Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21221P3HIGHCVSS 8.8fixed in 10.0.22621.51892025-04-08
CVE-2025-21221 [HIGH] CWE-122 CVE-2025-21221: Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute c Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21205P3HIGHCVSS 8.8fixed in 10.0.22621.51892025-04-08
CVE-2025-21205 [HIGH] CWE-122 CVE-2025-21205: Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute c Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-29966P3HIGHCVSS 8.8fixed in 10.0.22621.53352025-05-13
CVE-2025-29966 [HIGH] CWE-122 CVE-2025-29966: Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21417P3HIGHCVSS 8.8fixed in 10.0.22621.47512025-01-14
CVE-2025-21417 [HIGH] CWE-122 CVE-2025-21417: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21409P3HIGHCVSS 8.8fixed in 10.0.22621.47512025-01-14
CVE-2025-21409 [HIGH] CWE-122 CVE-2025-21409: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21339P3HIGHCVSS 8.8fixed in 10.0.22621.47512025-01-14
CVE-2025-21339 [HIGH] CWE-122 CVE-2025-21339: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21411P3HIGHCVSS 8.8fixed in 10.0.22621.47512025-01-14
CVE-2025-21411 [HIGH] CWE-122 CVE-2025-21411: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21413P3HIGHCVSS 8.8fixed in 10.0.22621.47512025-01-14
CVE-2025-21413 [HIGH] CWE-122 CVE-2025-21413: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-48817P3HIGHCVSS 8.8fixed in 10.0.22621.56242025-07-08
CVE-2025-48817 [HIGH] CWE-23 CVE-2025-48817: Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code ove Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-54916P3HIGHCVSS 7.8fixed in 10.0.22621.59092025-09-09
CVE-2025-54916 [HIGH] CWE-121 CVE-2025-54916: Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2025-21277P3HIGHCVSS 7.5fixed in 10.0.22621.47512025-01-14
CVE-2025-21277 [HIGH] CWE-126 CVE-2025-21277: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-58726P3HIGHCVSS 7.5fixed in 10.0.22621.60602025-10-14
CVE-2025-58726 [HIGH] CWE-284 CVE-2025-58726: Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges ov Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2023-35639P3HIGHCVSS 8.8fixed in 10.0.22621.28612023-12-12
CVE-2023-35639 [HIGH] CWE-122 CVE-2023-35639: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2024-26214P3HIGHCVSS 8.8fixed in 10.0.22621.34472024-04-09
CVE-2024-26214 [HIGH] CWE-122 CVE-2024-26214: Microsoft WDAC SQL Server ODBC Driver Remote Code Execution Vulnerability Microsoft WDAC SQL Server ODBC Driver Remote Code Execution Vulnerability
nvd
Microsoft Windows 11 22H2 vulnerabilities | cvebase