cbcvebase.

Microsoft Windows 11 Version 22H2 vulnerabilities

1,776 known vulnerabilities affecting microsoft/windows_11_version_22h2.

Total CVEs
1,776
CISA KEV
72
actively exploited
Public exploits
51
Exploited in wild
87
Severity breakdown
CRITICAL42HIGH1247MEDIUM479LOW8

Vulnerabilities

Page 4 of 89
CVE-2025-21418P1HIGHCVSS 7.8KEV≥ 10.0.22621.0, < 10.0.22621.48902025-02-11
CVE-2025-21418 [HIGH] CWE-122 CVE-2025-21418: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd
CVE-2024-38217P2MEDIUMCVSS 5.4KEV≥ 10.0.22621.0, < 10.0.22621.41692024-09-10
CVE-2024-38217 [MEDIUM] CWE-693 CVE-2024-38217: Windows Mark of the Web Security Feature Bypass Vulnerability Windows Mark of the Web Security Feature Bypass Vulnerability
nvd
CVE-2023-36584P2MEDIUMCVSS 5.4KEV≥ 10.0.22621.0, < 10.0.22621.24282023-10-10
CVE-2023-36584 [MEDIUM] CVE-2023-36584: Windows Mark of the Web Security Feature Bypass Vulnerability Windows Mark of the Web Security Feature Bypass Vulnerability
nvd
CVE-2022-41049P2MEDIUMCVSS 5.4KEV≥ 10.0.22621.0, < 10.0.22621.8192022-11-09
CVE-2022-41049 [MEDIUM] CVE-2022-41049: Windows Mark of the Web Security Feature Bypass Vulnerability Windows Mark of the Web Security Feature Bypass Vulnerability
nvd
CVE-2023-36563P2MEDIUMCVSS 5.5KEV≥ 10.0.22621.0, < 10.0.22621.24282023-10-10
CVE-2023-36563 [MEDIUM] CWE-20 CVE-2023-36563: Microsoft WordPad Information Disclosure Vulnerability Microsoft WordPad Information Disclosure Vulnerability
nvd
CVE-2025-24991P2MEDIUMCVSS 5.5KEV≥ 10.0.22621.0, < 10.0.22621.50392025-03-11
CVE-2025-24991 [MEDIUM] CWE-125 CVE-2025-24991: Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
nvd
CVE-2025-24984P2MEDIUMCVSS 4.6KEV≥ 10.0.22621.0, < 10.0.22621.50392025-03-11
CVE-2025-24984 [MEDIUM] CWE-532 CVE-2025-24984: Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
nvd
CVE-2024-43451MEDIUMCVSS 6.5KEVPoCRansomware≥ 10.0.22621.0, < 10.0.22621.44602024-11-12
CVE-2024-43451 [MEDIUM] CWE-73 NTLM Hash Disclosure Spoofing Vulnerability NTLM Hash Disclosure Spoofing Vulnerability NTLM Hash Disclosure Spoofing Vulnerability
cvelistv5
CVE-2023-21768P1HIGHCVSS 7.8ExploitedPoC≥ 10.0.22621.0, < 10.0.22621.11052023-01-10
CVE-2023-21768 [HIGH] CWE-822 CVE-2023-21768: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd
CVE-2025-24071P1MEDIUMCVSS 6.5ExploitedPoC≥ 10.0.22621.0, < 10.0.22621.50392025-03-11
CVE-2025-24071 [MEDIUM] CWE-200 CVE-2025-24071: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauth Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2024-30090P1HIGHCVSS 7.0ExploitedPoCRansomware≥ 10.0.22621.0, < 10.0.22621.37372024-06-11
CVE-2024-30090 [HIGH] CWE-822 CVE-2024-30090: Microsoft Streaming Service Elevation of Privilege Vulnerability Microsoft Streaming Service Elevation of Privilege Vulnerability
nvd
CVE-2024-26229P1HIGHCVSS 7.8ExploitedPoC≥ 10.0.22621.0, < 10.0.22621.34472024-04-09
CVE-2024-26229 [HIGH] CWE-122 CVE-2024-26229: Windows CSC Service Elevation of Privilege Vulnerability Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2024-38112HIGHCVSS 7.5KEV≥ 10.0.22621.0, < 10.0.22621.38802024-07-09
CVE-2024-38112 [HIGH] CWE-451 Windows MSHTML Platform Spoofing Vulnerability Windows MSHTML Platform Spoofing Vulnerability Windows MSHTML Platform Spoofing Vulnerability
cvelistv5
CVE-2024-43461HIGHCVSS 8.8KEV≥ 10.0.22621.0, < 10.0.22621.41692024-09-10
CVE-2024-43461 [HIGH] CWE-451 Windows MSHTML Platform Spoofing Vulnerability Windows MSHTML Platform Spoofing Vulnerability Windows MSHTML Platform Spoofing Vulnerability
cvelistv5
CVE-2024-38178HIGHCVSS 7.5KEV≥ 10.0.22621.0, < 10.0.22621.40372024-08-13
CVE-2024-38178 [HIGH] CWE-843 Scripting Engine Memory Corruption Vulnerability Scripting Engine Memory Corruption Vulnerability Scripting Engine Memory Corruption Vulnerability
cvelistv5
CVE-2024-43573MEDIUMCVSS 6.5KEV≥ 10.0.22621.0, < 10.0.22621.43172024-10-08
CVE-2024-43573 [MEDIUM] CWE-79 Windows MSHTML Platform Spoofing Vulnerability Windows MSHTML Platform Spoofing Vulnerability Windows MSHTML Platform Spoofing Vulnerability
cvelistv5
CVE-2024-21407P1HIGHCVSS 8.1ExploitedRansomware≥ 10.0.22621.0, < 10.0.22621.32962024-03-12
CVE-2024-21407 [HIGH] CWE-416 CVE-2024-21407: Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2024-21447P2HIGHCVSS 7.8Exploited≥ 10.0.22621.0, < 10.0.22621.34472024-04-09
CVE-2024-21447 [HIGH] CWE-59 CVE-2024-21447: Windows Authentication Elevation of Privilege Vulnerability Windows Authentication Elevation of Privilege Vulnerability
nvd
CVE-2024-38196P2HIGHCVSS 7.8Exploited≥ 10.0.22621.0, < 10.0.22621.40372024-08-13
CVE-2024-38196 [HIGH] CWE-20 CVE-2024-38196: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-21554P1CRITICALCVSS 9.8PoC≥ 10.0.22621.0, < 10.0.22621.15552023-04-11
CVE-2023-21554 [CRITICAL] CWE-20 CVE-2023-21554: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
Microsoft Windows 11 Version 22H2 vulnerabilities | cvebase