Microsoft Windows 11 Version 22H2 vulnerabilities
1,776 known vulnerabilities affecting microsoft/windows_11_version_22h2.
Total CVEs
1,776
CISA KEV
72
actively exploited
Public exploits
51
Exploited in wild
87
Severity breakdown
CRITICAL42HIGH1247MEDIUM479LOW8
Vulnerabilities
Page 50 of 89
CVE-2023-36575P3HIGHCVSS 7.3≥ 10.0.22621.0, < 10.0.22621.24282023-10-10
CVE-2023-36575 [HIGH] CWE-94 CVE-2023-36575: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2023-36572P3HIGHCVSS 7.3≥ 10.0.22621.0, < 10.0.22621.24282023-10-10
CVE-2023-36572 [HIGH] CWE-94 CVE-2023-36572: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2023-36591P3HIGHCVSS 7.3≥ 10.0.22621.0, < 10.0.22621.24282023-10-10
CVE-2023-36591 [HIGH] CWE-94 CVE-2023-36591: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2024-43615P3HIGHCVSS 7.1≥ 10.0.22621.0, < 10.0.22621.43172024-10-08
CVE-2024-43615 [HIGH] CWE-73 CVE-2024-43615: Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
nvd
CVE-2025-49680P3HIGHCVSS 7.3≥ 10.0.22621.0, < 10.0.22621.56242025-07-08
CVE-2025-49680 [HIGH] CWE-59 CVE-2025-49680: Improper link resolution before file access ('link following') in Windows Performance Recorder allow
Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized attacker to deny service locally.
nvd
CVE-2025-58725P3HIGHCVSS 7.0≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-58725 [HIGH] CWE-122 CVE-2025-58725: Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locall
Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50166P3MEDIUMCVSS 6.5≥ 10.0.22621.0, < 10.0.22621.57682025-08-12
CVE-2025-50166 [MEDIUM] CWE-190 CVE-2025-50166: Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized a
Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized attacker to disclose information over a network.
nvd
CVE-2025-21181P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.48902025-02-11
CVE-2025-21181 [HIGH] CWE-400 CVE-2025-21181: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-29809P3HIGHCVSS 7.1≥ 10.0.22621.0, < 10.0.22621.51892025-04-08
CVE-2025-29809 [HIGH] CWE-922 CVE-2025-29809: Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypas
Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2024-49096P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.46022024-12-12
CVE-2024-49096 [HIGH] CWE-400 CVE-2024-49096: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2024-49075P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.46022024-12-12
CVE-2024-49075 [HIGH] CWE-400 CVE-2024-49075: Windows Remote Desktop Services Denial of Service Vulnerability
Windows Remote Desktop Services Denial of Service Vulnerability
nvd
CVE-2023-36709P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.24282023-10-10
CVE-2023-36709 [HIGH] CWE-476 CVE-2023-36709: Microsoft AllJoyn API Denial of Service Vulnerability
Microsoft AllJoyn API Denial of Service Vulnerability
nvd
CVE-2025-21300P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21300 [HIGH] CWE-400 CVE-2025-21300: Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability
Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability
nvd
CVE-2024-38068P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.38802024-07-09
CVE-2024-38068 [HIGH] CWE-400 CVE-2024-38068: Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
nvd
CVE-2024-20687P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.30072024-01-09
CVE-2024-20687 [HIGH] CWE-125 CVE-2024-20687: Microsoft AllJoyn API Denial of Service Vulnerability
Microsoft AllJoyn API Denial of Service Vulnerability
nvd
CVE-2024-38145P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.40372024-08-13
CVE-2024-38145 [HIGH] CWE-476 CVE-2024-38145: Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
nvd
CVE-2024-38146P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.40372024-08-13
CVE-2024-38146 [HIGH] CWE-476 CVE-2024-38146: Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
nvd
CVE-2024-21348P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.31552024-02-13
CVE-2024-21348 [HIGH] CWE-122 CVE-2024-21348: Internet Connection Sharing (ICS) Denial of Service Vulnerability
Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd
CVE-2023-21701P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.12652023-02-14
CVE-2023-21701 [HIGH] CWE-126 CVE-2023-21701: Microsoft Protected Extensible Authentication Protocol (PEAP) Denial of Service Vulnerability
Microsoft Protected Extensible Authentication Protocol (PEAP) Denial of Service Vulnerability
nvd
CVE-2023-24901P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.17022023-05-09
CVE-2023-24901 [HIGH] CWE-126 CVE-2023-24901: Windows NFS Portmapper Information Disclosure Vulnerability
Windows NFS Portmapper Information Disclosure Vulnerability
nvd