cbcvebase.

Microsoft Windows 11 Version 22H2 vulnerabilities

1,776 known vulnerabilities affecting microsoft/windows_11_version_22h2.

Total CVEs
1,776
CISA KEV
72
actively exploited
Public exploits
51
Exploited in wild
87
Severity breakdown
CRITICAL42HIGH1247MEDIUM479LOW8

Vulnerabilities

Page 28 of 89
CVE-2025-33054P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.56242025-07-08
CVE-2025-33054 [HIGH] CWE-357 CVE-2025-33054: Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized atta Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2023-36718P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.24282023-10-10
CVE-2023-36718 [HIGH] CWE-94 CVE-2023-36718: Microsoft Virtual Trusted Platform Module Remote Code Execution Vulnerability Microsoft Virtual Trusted Platform Module Remote Code Execution Vulnerability
nvd
CVE-2025-47972P3HIGHCVSS 8.0≥ 10.0.22621.0, < 10.0.22621.56242025-07-08
CVE-2025-47972 [HIGH] CWE-362 CVE-2025-47972: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2025-49691P3HIGHCVSS 8.0≥ 10.0.22621.0, < 10.0.22621.56242025-07-08
CVE-2025-49691 [HIGH] CWE-122 CVE-2025-49691: Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an adjacent network.
nvd
CVE-2025-47955P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.53352025-06-10
CVE-2025-47955 [HIGH] CWE-269 CVE-2025-47955: Improper privilege management in Windows Remote Access Connection Manager allows an authorized attac Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50168P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.57682025-08-12
CVE-2025-50168 [HIGH] CWE-122 CVE-2025-50168: Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an au Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-26686P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.51892025-04-08
CVE-2025-26686 [HIGH] CWE-591 CVE-2025-26686: Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-24995P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.50392025-03-11
CVE-2025-24995 [HIGH] CWE-122 CVE-2025-24995: Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacke Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50173P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.57682025-08-12
CVE-2025-50173 [HIGH] CWE-1390 CVE-2025-50173: Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59201P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-59201 [HIGH] CWE-284 CVE-2025-59201: Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53152P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.57682025-08-12
CVE-2025-53152 [HIGH] CWE-416 CVE-2025-53152: Use after free in Desktop Windows Manager allows an authorized attacker to execute code locally. Use after free in Desktop Windows Manager allows an authorized attacker to execute code locally.
nvd
CVE-2025-48805P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.56242025-07-08
CVE-2025-48805 [HIGH] CWE-122 CVE-2025-48805: Heap-based buffer overflow in Microsoft MPEG-2 Video Extension allows an authorized attacker to exec Heap-based buffer overflow in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally.
nvd
CVE-2025-48806P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.56242025-07-08
CVE-2025-48806 [HIGH] CWE-416 CVE-2025-48806: Use after free in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code loc Use after free in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally.
nvd
CVE-2025-49732P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.56242025-07-08
CVE-2025-49732 [HIGH] CWE-122 CVE-2025-49732: Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-28238P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.15552023-04-11
CVE-2023-28238 [HIGH] CWE-591 CVE-2023-28238: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2025-55326P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-55326 [HIGH] CWE-416 CVE-2025-55326: Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to exe Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-27484P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.51892025-04-08
CVE-2025-27484 [HIGH] CWE-591 CVE-2025-27484: Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2024-30035P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.35932024-05-14
CVE-2024-30035 [HIGH] CWE-416 CVE-2024-30035: Windows DWM Core Library Elevation of Privilege Vulnerability Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2023-21812P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.12652023-02-14
CVE-2023-21812 [HIGH] CWE-122 CVE-2023-21812: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-38147P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.40372024-08-13
CVE-2024-38147 [HIGH] CWE-416 CVE-2024-38147: Microsoft DWM Core Library Elevation of Privilege Vulnerability Microsoft DWM Core Library Elevation of Privilege Vulnerability
nvd
Microsoft Windows 11 Version 22H2 vulnerabilities | cvebase