Microsoft Windows 11 Version 22H2 vulnerabilities
1,775 known vulnerabilities affecting microsoft/windows_11_version_22h2.
Total CVEs
1,775
CISA KEV
72
actively exploited
Public exploits
32
Exploited in wild
54
Severity breakdown
CRITICAL42HIGH1246MEDIUM479LOW8
Vulnerabilities
Page 26 of 89
CVE-2025-21289HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21289 [HIGH] CWE-400 CVE-2025-21289: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21343HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21343 [HIGH] CWE-269 CVE-2025-21343: Windows Web Threat Defense User Service Information Disclosure Vulnerability
Windows Web Threat Defense User Service Information Disclosure Vulnerability
nvd
CVE-2025-21389HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21389 [HIGH] CWE-400 CVE-2025-21389: Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an un
Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-21295HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21295 [HIGH] CWE-416 CVE-2025-21295: SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
nvd
CVE-2025-21338HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21338 [HIGH] CWE-190 GDI+ Remote Code Execution Vulnerability
GDI+ Remote Code Execution Vulnerability
GDI+ Remote Code Execution Vulnerability
cvelistv5
CVE-2025-21302HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21302 [HIGH] CWE-122 CVE-2025-21302: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21294HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21294 [HIGH] CWE-591 CVE-2025-21294: Microsoft Digest Authentication Remote Code Execution Vulnerability
Microsoft Digest Authentication Remote Code Execution Vulnerability
nvd
CVE-2025-21332HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21332 [HIGH] CWE-41 CVE-2025-21332: MapUrlToZone Security Feature Bypass Vulnerability
MapUrlToZone Security Feature Bypass Vulnerability
nvd
CVE-2025-21292HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21292 [HIGH] CWE-94 CVE-2025-21292: Windows Search Service Elevation of Privilege Vulnerability
Windows Search Service Elevation of Privilege Vulnerability
nvd
CVE-2025-21305HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21305 [HIGH] CWE-122 CVE-2025-21305: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21252HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21252 [HIGH] CWE-122 CVE-2025-21252: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21235HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21235 [HIGH] CWE-20 CVE-2025-21235: Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
nvd
CVE-2025-21382HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21382 [HIGH] CWE-122 CVE-2025-21382: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2025-21266HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21266 [HIGH] CWE-122 CVE-2025-21266: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21230HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21230 [HIGH] CWE-20 CVE-2025-21230: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21296HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21296 [HIGH] CWE-416 BranchCache Remote Code Execution Vulnerability
BranchCache Remote Code Execution Vulnerability
BranchCache Remote Code Execution Vulnerability
cvelistv5
CVE-2025-21276HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21276 [HIGH] CWE-191 CVE-2025-21276: Windows MapUrlToZone Denial of Service Vulnerability
Windows MapUrlToZone Denial of Service Vulnerability
nvd
CVE-2025-21277HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21277 [HIGH] CWE-126 CVE-2025-21277: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21240HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21240 [HIGH] CWE-122 CVE-2025-21240: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21411HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21411 [HIGH] CWE-122 CVE-2025-21411: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd