cbcvebase.

Microsoft Windows 11 Version 22H2 vulnerabilities

1,776 known vulnerabilities affecting microsoft/windows_11_version_22h2.

Total CVEs
1,776
CISA KEV
72
actively exploited
Public exploits
51
Exploited in wild
87
Severity breakdown
CRITICAL42HIGH1247MEDIUM479LOW8

Vulnerabilities

Page 27 of 89
CVE-2024-30032P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.35932024-05-14
CVE-2024-30032 [HIGH] CWE-416 CVE-2024-30032: Windows DWM Core Library Elevation of Privilege Vulnerability Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2024-20653P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.30072024-01-09
CVE-2024-20653 [HIGH] CWE-125 CVE-2024-20653: Microsoft Common Log File System Elevation of Privilege Vulnerability Microsoft Common Log File System Elevation of Privilege Vulnerability
nvd
CVE-2024-43629P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.44602024-11-12
CVE-2024-43629 [HIGH] CWE-822 CVE-2024-43629: Windows DWM Core Library Elevation of Privilege Vulnerability Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2023-38144P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.22832023-09-12
CVE-2023-38144 [HIGH] CWE-126 CVE-2023-38144: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-38257P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.41692024-09-10
CVE-2024-38257 [HIGH] CWE-908 CVE-2024-38257: Microsoft AllJoyn API Information Disclosure Vulnerability Microsoft AllJoyn API Information Disclosure Vulnerability
nvd
CVE-2024-38141P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.40372024-08-13
CVE-2024-38141 [HIGH] CWE-416 CVE-2024-38141: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd
CVE-2024-38150P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.40372024-08-13
CVE-2024-38150 [HIGH] CWE-416 CVE-2024-38150: Windows DWM Core Library Elevation of Privilege Vulnerability Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2025-21420P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.48902025-02-11
CVE-2025-21420 [HIGH] CWE-59 CVE-2025-21420: Windows Disk Cleanup Tool Elevation of Privilege Vulnerability Windows Disk Cleanup Tool Elevation of Privilege Vulnerability
nvd
CVE-2023-38143P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.22832023-09-12
CVE-2023-38143 [HIGH] CWE-122 CVE-2023-38143: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-43560P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.43172024-10-08
CVE-2024-43560 [HIGH] CWE-122 CVE-2024-43560: Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-35380P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.21342023-08-08
CVE-2023-35380 [HIGH] CWE-416 CVE-2023-35380: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-29996P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.35932024-05-14
CVE-2024-29996 [HIGH] CWE-125 CVE-2024-29996: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-21292P3HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21292 [HIGH] CWE-94 CVE-2025-21292: Windows Search Service Elevation of Privilege Vulnerability Windows Search Service Elevation of Privilege Vulnerability
nvd
CVE-2025-49687P3HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.56242025-07-08
CVE-2025-49687 [HIGH] CWE-125 CVE-2025-49687: Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate p Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-27737P3HIGHCVSS 8.6≥ 10.0.22621.0, < 10.0.22621.51892025-04-08
CVE-2025-27737 [HIGH] CWE-20 CVE-2025-27737: Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally.
nvd
CVE-2023-29351P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.18482023-06-14
CVE-2023-29351 [HIGH] CWE-59 CVE-2023-29351: Windows Group Policy Elevation of Privilege Vulnerability Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2025-33067P3HIGHCVSS 8.4≥ 10.0.22621.0, < 10.0.22621.54722025-06-10
CVE-2025-33067 [HIGH] CWE-269 CVE-2025-33067: Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privilege Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2023-23410P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.14132023-03-14
CVE-2023-23410 [HIGH] CWE-190 CVE-2023-23410: Windows HTTP.sys Elevation of Privilege Vulnerability Windows HTTP.sys Elevation of Privilege Vulnerability
nvd
CVE-2025-26673P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.51892025-04-08
CVE-2025-26673 [HIGH] CWE-400 CVE-2025-26673: Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-27469P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.51892025-04-08
CVE-2025-27469 [HIGH] CWE-400 CVE-2025-27469: Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
nvd
Microsoft Windows 11 Version 22H2 vulnerabilities | cvebase