cbcvebase.

Microsoft Windows 11 Version 22H2 vulnerabilities

1,776 known vulnerabilities affecting microsoft/windows_11_version_22h2.

Total CVEs
1,776
CISA KEV
72
actively exploited
Public exploits
51
Exploited in wild
87
Severity breakdown
CRITICAL42HIGH1247MEDIUM479LOW8

Vulnerabilities

Page 22 of 89
CVE-2022-23257P3HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.14132022-04-15
CVE-2022-23257 [HIGH] CVE-2022-23257: Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2022-37987P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.6742022-10-11
CVE-2022-37987 [HIGH] CVE-2022-37987: Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
nvd
CVE-2024-49105P3HIGHCVSS 8.4≥ 10.0.22621.0, < 10.0.22621.46022024-12-12
CVE-2024-49105 [HIGH] CWE-284 CVE-2024-49105: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2025-58716P3HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-58716 [HIGH] CWE-20 CVE-2025-58716: Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privi Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-41113P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.11052022-11-09
CVE-2022-41113 [HIGH] CVE-2022-41113: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2023-36697P3HIGHCVSS 8.0≥ 10.0.22621.0, < 10.0.22621.24282023-10-10
CVE-2023-36697 [HIGH] CWE-20 CVE-2023-36697: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2023-21556P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.11052023-01-10
CVE-2023-21556 [HIGH] CWE-191 CVE-2023-21556: Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
nvd
CVE-2022-44683P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.9932022-12-13
CVE-2022-44683 [HIGH] CWE-416 CVE-2022-44683: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-35297P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.19922023-07-11
CVE-2023-35297 [HIGH] CWE-843 CVE-2023-35297: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-28283P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.17022023-05-09
CVE-2023-28283 [HIGH] CWE-591 CVE-2023-28283: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2023-38184P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.21342023-08-08
CVE-2023-38184 [HIGH] CWE-416 CVE-2023-38184: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2024-26170P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.32962024-03-12
CVE-2024-26170 [HIGH] CWE-20 CVE-2024-26170: Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability
nvd
CVE-2024-49089P3HIGHCVSS 7.2≥ 10.0.22621.0, < 10.0.22621.46022024-12-12
CVE-2024-49089 [HIGH] CWE-122 CVE-2024-49089: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2025-29969P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.53352025-05-13
CVE-2025-29969 [HIGH] CWE-367 CVE-2025-29969: Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attac Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network.
nvd
CVE-2023-32056P3CRITICALCVSS 9.8≥ 10.0.22621.0, < 10.0.22621.19922023-07-11
CVE-2023-32056 [CRITICAL] CWE-59 CVE-2023-32056: Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
nvd
CVE-2024-38241P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.41692024-09-10
CVE-2024-38241 [HIGH] CWE-20 CVE-2024-38241: Kernel Streaming Service Driver Elevation of Privilege Vulnerability Kernel Streaming Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-38125P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.40372024-08-13
CVE-2024-38125 [HIGH] CWE-197 CVE-2024-38125: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-33154P3CRITICALCVSS 9.8≥ 10.0.22621.0, < 10.0.22621.19922023-07-11
CVE-2023-33154 [CRITICAL] CWE-367 CVE-2023-33154: Windows Partition Management Driver Elevation of Privilege Vulnerability Windows Partition Management Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-43623P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.44602024-11-12
CVE-2024-43623 [HIGH] CWE-190 CVE-2024-43623: Windows NT OS Kernel Elevation of Privilege Vulnerability Windows NT OS Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-37970P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.6742022-10-11
CVE-2022-37970 [HIGH] CVE-2022-37970: Windows DWM Core Library Elevation of Privilege Vulnerability Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
Microsoft Windows 11 Version 22H2 vulnerabilities | cvebase