Microsoft Windows 11 Version 22H2 vulnerabilities
1,776 known vulnerabilities affecting microsoft/windows_11_version_22h2.
Total CVEs
1,776
CISA KEV
72
actively exploited
Public exploits
51
Exploited in wild
87
Severity breakdown
CRITICAL42HIGH1247MEDIUM479LOW8
Vulnerabilities
Page 33 of 89
CVE-2025-55228P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.59092025-09-09
CVE-2025-55228 [HIGH] CWE-362 CVE-2025-55228: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
nvd
CVE-2025-53150P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-53150 [HIGH] CWE-362 CVE-2025-53150: Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-48000P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.56242025-07-08
CVE-2025-48000 [HIGH] CWE-362 CVE-2025-48000: Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevat
Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54913P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.59092025-09-09
CVE-2025-54913 [HIGH] CWE-362 CVE-2025-54913: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapControlSettings allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59192P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-59192 [HIGH] CWE-126 CVE-2025-59192: Buffer over-read in Storport.sys Driver allows an authorized attacker to elevate privileges locally.
Buffer over-read in Storport.sys Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-58714P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-58714 [HIGH] CWE-284 CVE-2025-58714: Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attack
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-38119P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.41692024-09-10
CVE-2024-38119 [HIGH] CWE-416 CVE-2024-38119: Windows Network Address Translation (NAT) Remote Code Execution Vulnerability
Windows Network Address Translation (NAT) Remote Code Execution Vulnerability
nvd
CVE-2023-24932MEDIUMCVSS 6.7Exploited≥ 10.0.22621.0, < 10.0.22621.56242023-05-09
CVE-2023-24932 [MEDIUM] Secure Boot Security Feature Bypass Vulnerability
Secure Boot Security Feature Bypass Vulnerability
Secure Boot Security Feature Bypass Vulnerability
cvelistv5
CVE-2025-50161P3HIGHCVSS 7.3≥ 10.0.22621.0, < 10.0.22621.57682025-08-12
CVE-2025-50161 [HIGH] CWE-122 CVE-2025-50161: Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privile
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-38016P3HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.6742022-10-11
CVE-2022-38016 [HIGH] CVE-2022-38016: Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
nvd
CVE-2023-32009P3HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.18482023-06-14
CVE-2023-32009 [HIGH] CWE-284 CVE-2023-32009: Windows Collaborative Translation Framework Elevation of Privilege Vulnerability
Windows Collaborative Translation Framework Elevation of Privilege Vulnerability
nvd
CVE-2024-43584P3HIGHCVSS 8.4≥ 10.0.22621.0, < 10.0.22621.43172024-10-08
CVE-2024-43584 [HIGH] CWE-693 CVE-2024-43584: Windows Scripting Engine Security Feature Bypass Vulnerability
Windows Scripting Engine Security Feature Bypass Vulnerability
nvd
CVE-2024-20696P3HIGHCVSS 7.3≥ 10.0.22621.0, < 10.0.22621.30072024-01-09
CVE-2024-20696 [HIGH] CWE-122 CVE-2024-20696: Windows libarchive Remote Code Execution Vulnerability
Windows libarchive Remote Code Execution Vulnerability
nvd
CVE-2023-36407P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.27152023-11-14
CVE-2023-36407 [HIGH] CWE-20 CVE-2023-36407: Windows Hyper-V Elevation of Privilege Vulnerability
Windows Hyper-V Elevation of Privilege Vulnerability
nvd
CVE-2023-36396P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.27152023-11-14
CVE-2023-36396 [HIGH] CWE-41 CVE-2023-36396: Windows Compressed Folder Remote Code Execution Vulnerability
Windows Compressed Folder Remote Code Execution Vulnerability
nvd
CVE-2024-38184P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.38802024-08-13
CVE-2024-38184 [HIGH] CWE-125 CVE-2024-38184: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-38185P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.38802024-08-13
CVE-2024-38185 [HIGH] CWE-822 CVE-2024-38185: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-38187P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.38802024-08-13
CVE-2024-38187 [HIGH] CWE-822 CVE-2024-38187: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-36047P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.27152023-11-14
CVE-2023-36047 [HIGH] CWE-59 CVE-2023-36047: Windows Authentication Elevation of Privilege Vulnerability
Windows Authentication Elevation of Privilege Vulnerability
nvd
CVE-2024-49090P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.46022024-12-12
CVE-2024-49090 [HIGH] CWE-822 CVE-2024-49090: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd