Microsoft Windows 11 Version 22H2 vulnerabilities
1,776 known vulnerabilities affecting microsoft/windows_11_version_22h2.
Total CVEs
1,776
CISA KEV
72
actively exploited
Public exploits
51
Exploited in wild
87
Severity breakdown
CRITICAL42HIGH1247MEDIUM479LOW8
Vulnerabilities
Page 22 of 89
CVE-2022-23257P3HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.14132022-04-15
CVE-2022-23257 [HIGH] CVE-2022-23257: Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2022-37987P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.6742022-10-11
CVE-2022-37987 [HIGH] CVE-2022-37987: Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
nvd
CVE-2024-49105P3HIGHCVSS 8.4≥ 10.0.22621.0, < 10.0.22621.46022024-12-12
CVE-2024-49105 [HIGH] CWE-284 CVE-2024-49105: Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2025-58716P3HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-58716 [HIGH] CWE-20 CVE-2025-58716: Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privi
Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-41113P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.11052022-11-09
CVE-2022-41113 [HIGH] CVE-2022-41113: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2023-36697P3HIGHCVSS 8.0≥ 10.0.22621.0, < 10.0.22621.24282023-10-10
CVE-2023-36697 [HIGH] CWE-20 CVE-2023-36697: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2023-21556P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.11052023-01-10
CVE-2023-21556 [HIGH] CWE-191 CVE-2023-21556: Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
nvd
CVE-2022-44683P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.9932022-12-13
CVE-2022-44683 [HIGH] CWE-416 CVE-2022-44683: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-35297P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.19922023-07-11
CVE-2023-35297 [HIGH] CWE-843 CVE-2023-35297: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-28283P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.17022023-05-09
CVE-2023-28283 [HIGH] CWE-591 CVE-2023-28283: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2023-38184P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.21342023-08-08
CVE-2023-38184 [HIGH] CWE-416 CVE-2023-38184: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2024-26170P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.32962024-03-12
CVE-2024-26170 [HIGH] CWE-20 CVE-2024-26170: Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability
Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability
nvd
CVE-2024-49089P3HIGHCVSS 7.2≥ 10.0.22621.0, < 10.0.22621.46022024-12-12
CVE-2024-49089 [HIGH] CWE-122 CVE-2024-49089: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2025-29969P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.53352025-05-13
CVE-2025-29969 [HIGH] CWE-367 CVE-2025-29969: Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attac
Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network.
nvd
CVE-2023-32056P3CRITICALCVSS 9.8≥ 10.0.22621.0, < 10.0.22621.19922023-07-11
CVE-2023-32056 [CRITICAL] CWE-59 CVE-2023-32056: Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
nvd
CVE-2024-38241P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.41692024-09-10
CVE-2024-38241 [HIGH] CWE-20 CVE-2024-38241: Kernel Streaming Service Driver Elevation of Privilege Vulnerability
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-38125P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.40372024-08-13
CVE-2024-38125 [HIGH] CWE-197 CVE-2024-38125: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-33154P3CRITICALCVSS 9.8≥ 10.0.22621.0, < 10.0.22621.19922023-07-11
CVE-2023-33154 [CRITICAL] CWE-367 CVE-2023-33154: Windows Partition Management Driver Elevation of Privilege Vulnerability
Windows Partition Management Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-43623P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.44602024-11-12
CVE-2024-43623 [HIGH] CWE-190 CVE-2024-43623: Windows NT OS Kernel Elevation of Privilege Vulnerability
Windows NT OS Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-37970P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.6742022-10-11
CVE-2022-37970 [HIGH] CVE-2022-37970: Windows DWM Core Library Elevation of Privilege Vulnerability
Windows DWM Core Library Elevation of Privilege Vulnerability
nvd