cbcvebase.

Microsoft Windows 11 Version 22H2 vulnerabilities

1,776 known vulnerabilities affecting microsoft/windows_11_version_22h2.

Total CVEs
1,776
CISA KEV
72
actively exploited
Public exploits
51
Exploited in wild
87
Severity breakdown
CRITICAL42HIGH1247MEDIUM479LOW8

Vulnerabilities

Page 24 of 89
CVE-2023-21546P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.11052023-01-10
CVE-2023-21546 [HIGH] CWE-591 CVE-2023-21546: Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
nvd
CVE-2023-21679P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.11052023-01-10
CVE-2023-21679 [HIGH] CWE-416 CVE-2023-21679: Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
nvd
CVE-2023-21555P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.11052023-01-10
CVE-2023-21555 [HIGH] CWE-367 CVE-2023-21555: Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
nvd
CVE-2023-21548P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.11052023-01-10
CVE-2023-21548 [HIGH] CWE-591 CVE-2023-21548: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2023-21535P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.11052023-01-10
CVE-2023-21535 [HIGH] CWE-591 CVE-2023-21535: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2022-44676P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.9932022-12-13
CVE-2022-44676 [HIGH] CWE-362 CVE-2022-44676: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2022-41039P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.8192022-11-09
CVE-2022-41039 [HIGH] CWE-362 CVE-2022-41039: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-23405P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.14132023-03-14
CVE-2023-23405 [HIGH] CWE-190 CVE-2023-23405: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2023-24908P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.14132023-03-14
CVE-2023-24908 [HIGH] CWE-190 CVE-2023-24908: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2023-24869P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.14132023-03-14
CVE-2023-24869 [HIGH] CWE-190 CVE-2023-24869: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2023-21712P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.8192023-04-27
CVE-2023-21712 [HIGH] CWE-362 CVE-2023-21712: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2022-41088P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.8192022-11-09
CVE-2022-41088 [HIGH] CWE-362 CVE-2022-41088: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-24903P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.17022023-05-09
CVE-2023-24903 [HIGH] CWE-415 CVE-2023-24903: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2023-23404P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.14132023-03-14
CVE-2023-23404 [HIGH] CWE-416 CVE-2023-23404: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2025-53149P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.57682025-08-12
CVE-2025-53149 [HIGH] CWE-122 CVE-2025-53149: Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacke Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24067P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.50392025-03-11
CVE-2025-24067 [HIGH] CWE-122 CVE-2025-24067: Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate p Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24066P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.50392025-03-11
CVE-2025-24066 [HIGH] CWE-122 CVE-2025-24066: Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate p Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24063P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.53352025-05-13
CVE-2025-24063 [HIGH] CWE-122 CVE-2025-24063: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-26666P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.51892025-04-08
CVE-2025-26666 [HIGH] CWE-122 CVE-2025-26666: Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
nvd
CVE-2025-26674P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.51892025-04-08
CVE-2025-26674 [HIGH] CWE-122 CVE-2025-26674: Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
nvd
Microsoft Windows 11 Version 22H2 vulnerabilities | cvebase