Microsoft Windows 11 Version 22H2 vulnerabilities
1,776 known vulnerabilities affecting microsoft/windows_11_version_22h2.
Total CVEs
1,776
CISA KEV
72
actively exploited
Public exploits
51
Exploited in wild
87
Severity breakdown
CRITICAL42HIGH1247MEDIUM479LOW8
Vulnerabilities
Page 17 of 89
CVE-2024-21391P3HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.31552024-02-13
CVE-2024-21391 [HIGH] CWE-197 CVE-2024-21391: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21352P3HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.31552024-02-13
CVE-2024-21352 [HIGH] CWE-197 CVE-2024-21352: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-43519P3HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.43172024-10-08
CVE-2024-43519 [HIGH] CWE-197 CVE-2024-43519: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2025-21222P3HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.51892025-04-08
CVE-2025-21222 [HIGH] CWE-122 CVE-2025-21222: Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute c
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21221P3HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.51892025-04-08
CVE-2025-21221 [HIGH] CWE-122 CVE-2025-21221: Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute c
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21205P3HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.51892025-04-08
CVE-2025-21205 [HIGH] CWE-122 CVE-2025-21205: Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute c
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-38131P3HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.40372024-08-13
CVE-2024-38131 [HIGH] CWE-591 CVE-2024-38131: Clipboard Virtual Channel Extension Remote Code Execution Vulnerability
Clipboard Virtual Channel Extension Remote Code Execution Vulnerability
nvd
CVE-2024-38053P3HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.38802024-07-09
CVE-2024-38053 [HIGH] CWE-416 CVE-2024-38053: Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability
Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability
nvd
CVE-2025-48817P3HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.56242025-07-08
CVE-2025-48817 [HIGH] CWE-23 CVE-2025-48817: Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code ove
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-29964P3HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.53352025-05-13
CVE-2025-29964 [HIGH] CWE-122 CVE-2025-29964: Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a n
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-29963P3HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.53352025-05-13
CVE-2025-29963 [HIGH] CWE-122 CVE-2025-29963: Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a n
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-43518P3HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.43172024-10-08
CVE-2024-43518 [HIGH] CWE-122 CVE-2024-43518: Windows Telephony Server Remote Code Execution Vulnerability
Windows Telephony Server Remote Code Execution Vulnerability
nvd
CVE-2025-21224P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21224 [HIGH] CWE-416 CVE-2025-21224: Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
nvd
CVE-2025-54916P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.59092025-09-09
CVE-2025-54916 [HIGH] CWE-121 CVE-2025-54916: Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2024-38049P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.38802024-07-09
CVE-2024-38049 [HIGH] CWE-73 CVE-2024-38049: Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability
Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability
nvd
CVE-2025-58722P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-58722 [HIGH] CWE-122 CVE-2025-58722: Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locall
Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-49118P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.46022024-12-12
CVE-2024-49118 [HIGH] CWE-416 CVE-2024-49118: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2024-38045P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.41692024-09-10
CVE-2024-38045 [HIGH] CWE-122 CVE-2024-38045: Windows TCP/IP Remote Code Execution Vulnerability
Windows TCP/IP Remote Code Execution Vulnerability
nvd
CVE-2024-49124P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.46022024-12-12
CVE-2024-49124 [HIGH] CWE-362 CVE-2024-49124: Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability
Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability
nvd
CVE-2024-49127P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.46022024-12-12
CVE-2024-49127 [HIGH] CWE-416 CVE-2024-49127: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd