Microsoft Windows 11 Version 22H2 vulnerabilities
1,776 known vulnerabilities affecting microsoft/windows_11_version_22h2.
Total CVEs
1,776
CISA KEV
72
actively exploited
Public exploits
51
Exploited in wild
87
Severity breakdown
CRITICAL42HIGH1247MEDIUM479LOW8
Vulnerabilities
Page 26 of 89
CVE-2024-21307P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.30072024-01-09
CVE-2024-21307 [HIGH] CWE-416 CVE-2024-21307: Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2023-28274P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.15552023-04-11
CVE-2023-28274 [HIGH] CWE-20 CVE-2023-28274: Windows Win32k Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
nvd
CVE-2025-32713P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.54722025-06-10
CVE-2025-32713 [HIGH] CWE-122 CVE-2025-32713: Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-30015P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.35932024-05-14
CVE-2024-30015 [HIGH] CWE-197 CVE-2024-30015: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-30029P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.35932024-05-14
CVE-2024-30029 [HIGH] CWE-197 CVE-2024-30029: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-30014P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.35932024-05-14
CVE-2024-30014 [HIGH] CWE-197 CVE-2024-30014: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2025-26666P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.51892025-04-08
CVE-2025-26666 [HIGH] CWE-122 CVE-2025-26666: Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
nvd
CVE-2025-26674P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.51892025-04-08
CVE-2025-26674 [HIGH] CWE-122 CVE-2025-26674: Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
nvd
CVE-2024-38028P3HIGHCVSS 7.2≥ 10.0.22621.0, < 10.0.22621.38802024-07-09
CVE-2024-38028 [HIGH] CWE-125 CVE-2024-38028: Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
nvd
CVE-2024-38025P3HIGHCVSS 7.2≥ 10.0.22621.0, < 10.0.22621.38802024-07-09
CVE-2024-38025 [HIGH] CWE-122 CVE-2024-38025: Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
nvd
CVE-2025-24048P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.50392025-03-11
CVE-2025-24048 [HIGH] CWE-122 CVE-2025-24048: Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privile
Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24050P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.50392025-03-11
CVE-2025-24050 [HIGH] CWE-122 CVE-2025-24050: Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privile
Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-30098P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.60602024-07-09
CVE-2024-30098 [HIGH] CWE-327 CVE-2024-30098: Windows Cryptographic Services Security Feature Bypass Vulnerability
Windows Cryptographic Services Security Feature Bypass Vulnerability
nvd
CVE-2023-36401P3HIGHCVSS 7.2≥ 10.0.22621.0, < 10.0.22621.27152023-11-14
CVE-2023-36401 [HIGH] CWE-190 CVE-2023-36401: Microsoft Remote Registry Service Remote Code Execution Vulnerability
Microsoft Remote Registry Service Remote Code Execution Vulnerability
nvd
CVE-2025-59255P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-59255 [HIGH] CWE-122 CVE-2025-59255: Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate priv
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59242P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-59242 [HIGH] CWE-122 CVE-2025-59242: Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized att
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53789P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22631.56242025-08-12
CVE-2025-53789 [HIGH] CWE-306 CVE-2025-53789: Missing authentication for critical function in Windows StateRepository API allows an authorized att
Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-38019P3HIGHCVSS 7.2≥ 10.0.22621.0, < 10.0.22621.38802024-07-09
CVE-2024-38019 [HIGH] CWE-190 CVE-2024-38019: Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
nvd
CVE-2023-21557P3CRITICALCVSS 9.1≥ 10.0.22621.0, < 10.0.22621.11052023-01-10
CVE-2023-21557 [CRITICAL] CWE-190 CVE-2023-21557: Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
nvd
CVE-2024-38085P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.38802024-07-09
CVE-2024-38085 [HIGH] CWE-416 CVE-2024-38085: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd