cbcvebase.

Microsoft Windows 11 22H2 vulnerabilities

1,432 known vulnerabilities affecting microsoft/windows_11_22h2.

Total CVEs
1,432
CISA KEV
67
actively exploited
Public exploits
43
Exploited in wild
75
Severity breakdown
CRITICAL39HIGH1001MEDIUM387LOW5

Vulnerabilities

Page 9 of 72
CVE-2024-20678P3HIGHCVSS 8.8fixed in 10.0.22621.34472024-04-09
CVE-2024-20678 [HIGH] CWE-843 CVE-2024-20678: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2023-36423P3HIGHCVSS 8.8fixed in 10.0.22621.27152023-11-14
CVE-2023-36423 [HIGH] CWE-122 CVE-2023-36423: Microsoft Remote Registry Service Remote Code Execution Vulnerability Microsoft Remote Registry Service Remote Code Execution Vulnerability
nvd
CVE-2025-59295P3HIGHCVSS 8.8fixed in 10.0.22621.60602025-10-14
CVE-2025-59295 [HIGH] CWE-122 CVE-2025-59295: Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-24051P3HIGHCVSS 8.8fixed in 10.0.22621.50392025-03-11
CVE-2025-24051 [HIGH] CWE-122 CVE-2025-24051: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2023-35641P3HIGHCVSS 8.8fixed in 10.0.22621.28612023-12-12
CVE-2023-35641 [HIGH] CWE-682 CVE-2023-35641: Internet Connection Sharing (ICS) Remote Code Execution Vulnerability Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
nvd
CVE-2025-49724P3HIGHCVSS 8.8fixed in 10.0.22621.56242025-07-08
CVE-2025-49724 [HIGH] CWE-416 CVE-2025-49724: Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to exec Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2023-35630P3HIGHCVSS 8.8fixed in 10.0.22621.28612023-12-12
CVE-2023-35630 [HIGH] CWE-122 CVE-2023-35630: Internet Connection Sharing (ICS) Remote Code Execution Vulnerability Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
nvd
CVE-2026-50508P3HIGHCVSS 7.5fixed in 10.0.22631.72192026-06-09
CVE-2026-50508 [HIGH] CWE-200 CVE-2026-50508: Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized at Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2024-26230P3HIGHCVSS 7.8fixed in 10.0.22621.34472024-04-09
CVE-2024-26230 [HIGH] CWE-416 CVE-2024-26230: Windows Telephony Server Elevation of Privilege Vulnerability Windows Telephony Server Elevation of Privilege Vulnerability
nvd
CVE-2025-21285P3HIGHCVSS 7.5fixed in 10.0.22621.47512025-01-14
CVE-2025-21285 [HIGH] CWE-476 CVE-2025-21285: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21371P3HIGHCVSS 8.8fixed in 10.0.22621.48902025-02-11
CVE-2025-21371 [HIGH] CWE-122 CVE-2025-21371: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-50177P3HIGHCVSS 8.1fixed in 10.0.22621.57682025-08-12
CVE-2025-50177 [HIGH] CWE-362 CVE-2025-50177: Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a net Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21407P3HIGHCVSS 8.8fixed in 10.0.22621.48902025-02-11
CVE-2025-21407 [HIGH] CWE-122 CVE-2025-21407: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21406P3HIGHCVSS 8.8fixed in 10.0.22621.48902025-02-11
CVE-2025-21406 [HIGH] CWE-416 CVE-2025-21406: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21190P3HIGHCVSS 8.8fixed in 10.0.22621.48902025-02-11
CVE-2025-21190 [HIGH] CWE-122 CVE-2025-21190: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21201P3HIGHCVSS 8.8fixed in 10.0.22621.48902025-02-11
CVE-2025-21201 [HIGH] CWE-415 CVE-2025-21201: Windows Telephony Server Remote Code Execution Vulnerability Windows Telephony Server Remote Code Execution Vulnerability
nvd
CVE-2025-21200P3HIGHCVSS 8.8fixed in 10.0.22621.48902025-02-11
CVE-2025-21200 [HIGH] CWE-122 CVE-2025-21200: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2024-38259P3HIGHCVSS 8.8fixed in 10.0.22621.41692024-09-10
CVE-2024-38259 [HIGH] CWE-416 CVE-2024-38259: Microsoft Management Console Remote Code Execution Vulnerability Microsoft Management Console Remote Code Execution Vulnerability
nvd
CVE-2023-21695P3HIGHCVSS 8.8fixed in 10.0.22621.12652023-02-14
CVE-2023-21695 [HIGH] CWE-122 CVE-2023-21695: Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
nvd
CVE-2025-33066P3HIGHCVSS 8.8fixed in 10.0.22621.54722025-06-10
CVE-2025-33066 [HIGH] CWE-122 CVE-2025-33066: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd