cbcvebase.

Microsoft Windows 11 Version 22H2 vulnerabilities

1,776 known vulnerabilities affecting microsoft/windows_11_version_22h2.

Total CVEs
1,776
CISA KEV
72
actively exploited
Public exploits
51
Exploited in wild
87
Severity breakdown
CRITICAL42HIGH1247MEDIUM479LOW8

Vulnerabilities

Page 31 of 89
CVE-2025-59275P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-59275 [HIGH] CWE-122 CVE-2025-59275: Improper validation of specified type of input in Windows Authentication Methods allows an authorize Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-30092P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.43172024-10-08
CVE-2024-30092 [HIGH] CWE-20 CVE-2024-30092: Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2022-44675P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.9932022-12-13
CVE-2022-44675 [HIGH] CVE-2022-44675: Windows Bluetooth Driver Elevation of Privilege Vulnerability Windows Bluetooth Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-24912P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.15552023-04-11
CVE-2023-24912 [HIGH] CWE-122 CVE-2023-24912: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2024-21417P3HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.38802024-07-10
CVE-2024-21417 [HIGH] CWE-862 CVE-2024-21417: Windows Text Services Framework Elevation of Privilege Vulnerability Windows Text Services Framework Elevation of Privilege Vulnerability
nvd
CVE-2025-48822P3HIGHCVSS 8.6≥ 10.0.22621.0, < 10.0.22621.56242025-07-08
CVE-2025-48822 [HIGH] CWE-125 CVE-2025-48822: Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-24052P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-24052 [HIGH] CWE-121 CVE-2025-24052: Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. Fax modem hardware dependent on this specific driver will no longer work on Window
nvd
CVE-2023-36723P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.24282023-10-10
CVE-2023-36723 [HIGH] CWE-59 CVE-2023-36723: Windows Container Manager Service Elevation of Privilege Vulnerability Windows Container Manager Service Elevation of Privilege Vulnerability
nvd
CVE-2024-38127P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.40372024-08-13
CVE-2024-38127 [HIGH] CWE-126 CVE-2024-38127: Windows Hyper-V Elevation of Privilege Vulnerability Windows Hyper-V Elevation of Privilege Vulnerability
nvd
CVE-2025-27727P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.51892025-04-08
CVE-2025-27727 [HIGH] CWE-59 CVE-2025-27727: Improper link resolution before file access ('link following') in Windows Installer allows an author Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-29812P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.51892025-04-08
CVE-2025-29812 [HIGH] CWE-822 CVE-2025-29812: Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate priv Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-38245P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.41692024-09-10
CVE-2024-38245 [HIGH] CWE-20 CVE-2024-38245: Kernel Streaming Service Driver Elevation of Privilege Vulnerability Kernel Streaming Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-21363P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.31552024-02-13
CVE-2024-21363 [HIGH] CWE-843 CVE-2024-21363: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2024-38238P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.41692024-09-10
CVE-2024-38238 [HIGH] CWE-122 CVE-2024-38238: Kernel Streaming Service Driver Elevation of Privilege Vulnerability Kernel Streaming Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-38243P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.41692024-09-10
CVE-2024-38243 [HIGH] CWE-20 CVE-2024-38243: Kernel Streaming Service Driver Elevation of Privilege Vulnerability Kernel Streaming Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-20682P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.30072024-01-09
CVE-2024-20682 [HIGH] CWE-822 CVE-2024-20682: Windows Cryptographic Services Remote Code Execution Vulnerability Windows Cryptographic Services Remote Code Execution Vulnerability
nvd
CVE-2024-38057P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.38802024-07-09
CVE-2024-38057 [HIGH] CWE-125 CVE-2024-38057: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-21375P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.48902025-02-11
CVE-2025-21375 [HIGH] CWE-20 CVE-2025-21375: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-24044P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.50392025-03-11
CVE-2025-24044 [HIGH] CWE-416 CVE-2025-24044: Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-33075P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.54722025-06-10
CVE-2025-33075 [HIGH] CWE-59 CVE-2025-33075: Improper link resolution before file access ('link following') in Windows Installer allows an author Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows 11 Version 22H2 vulnerabilities | cvebase