cbcvebase.

Microsoft Windows 11 Version 22H2 vulnerabilities

1,776 known vulnerabilities affecting microsoft/windows_11_version_22h2.

Total CVEs
1,776
CISA KEV
72
actively exploited
Public exploits
51
Exploited in wild
87
Severity breakdown
CRITICAL42HIGH1247MEDIUM479LOW8

Vulnerabilities

Page 63 of 89
CVE-2024-43543P4MEDIUMCVSS 6.8≥ 10.0.22621.0, < 10.0.22621.43172024-10-08
CVE-2024-43543 [MEDIUM] CWE-601 CVE-2024-43543: Windows Mobile Broadband Driver Remote Code Execution Vulnerability Windows Mobile Broadband Driver Remote Code Execution Vulnerability
nvd
CVE-2024-43536P4MEDIUMCVSS 6.8≥ 10.0.22621.0, < 10.0.22621.43172024-10-08
CVE-2024-43536 [MEDIUM] CWE-601 CVE-2024-43536: Windows Mobile Broadband Driver Remote Code Execution Vulnerability Windows Mobile Broadband Driver Remote Code Execution Vulnerability
nvd
CVE-2024-21431P4MEDIUMCVSS 6.7≥ 10.0.22621.0, < 10.0.22621.32962024-03-12
CVE-2024-21431 [MEDIUM] CWE-732 CVE-2024-21431: Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
nvd
CVE-2025-48807P4MEDIUMCVSS 6.7≥ 10.0.22621.0, < 10.0.22621.59092025-08-12
CVE-2025-48807 [MEDIUM] CWE-923 CVE-2025-48807: Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an aut Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally.
nvd
CVE-2025-54104P4MEDIUMCVSS 6.7≥ 10.0.22621.0, < 10.0.22621.59092025-09-09
CVE-2025-54104 [MEDIUM] CWE-843 CVE-2025-54104: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55226P4MEDIUMCVSS 6.7≥ 10.0.22621.0, < 10.0.22621.59092025-09-09
CVE-2025-55226 [MEDIUM] CWE-362 CVE-2025-55226: Concurrent execution using shared resource with improper synchronization ('race condition') in Graph Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to execute code locally.
nvd
CVE-2025-48811P4MEDIUMCVSS 6.7≥ 10.0.22621.0, < 10.0.22621.56242025-07-08
CVE-2025-48811 [MEDIUM] CWE-353 CVE-2025-48811: Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-48803P4MEDIUMCVSS 6.7≥ 10.0.22621.0, < 10.0.22621.56242025-07-08
CVE-2025-48803 [MEDIUM] CWE-353 CVE-2025-48803: Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-29954P4MEDIUMCVSS 5.9≥ 10.0.22621.0, < 10.0.22621.53352025-05-13
CVE-2025-29954 [MEDIUM] CWE-400 CVE-2025-29954: Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
nvd
CVE-2024-26160P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.32962024-03-12
CVE-2024-26160 [MEDIUM] CWE-126 CVE-2024-26160: Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability
nvd
CVE-2024-21356P4MEDIUMCVSS 6.5≥ 10.0.22621.0, < 10.0.22621.31552024-02-13
CVE-2024-21356 [MEDIUM] CWE-476 CVE-2024-21356: Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
nvd
CVE-2024-20657P4HIGHCVSS 7.0≥ 10.0.22621.0, < 10.0.22621.30072024-01-09
CVE-2024-20657 [HIGH] CWE-284 CVE-2024-20657: Windows Group Policy Elevation of Privilege Vulnerability Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2023-21739P4HIGHCVSS 7.0≥ 10.0.22621.0, < 10.0.22621.11052023-01-10
CVE-2023-21739 [HIGH] CWE-591 CVE-2023-21739: Windows Bluetooth Driver Elevation of Privilege Vulnerability Windows Bluetooth Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-36902P4HIGHCVSS 7.0≥ 10.0.22621.0, < 10.0.22621.24282023-10-10
CVE-2023-36902 [HIGH] CWE-416 CVE-2023-36902: Windows Runtime Remote Code Execution Vulnerability Windows Runtime Remote Code Execution Vulnerability
nvd
CVE-2022-41114P4HIGHCVSS 7.0≥ 10.0.22621.0, < 10.0.22621.8192022-11-09
CVE-2022-41114 [HIGH] CWE-362 CVE-2022-41114: Windows Bind Filter Driver Elevation of Privilege Vulnerability Windows Bind Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-21341P4MEDIUMCVSS 6.8≥ 10.0.22621.0, < 10.0.22621.31552024-02-13
CVE-2024-21341 [MEDIUM] CWE-122 CVE-2024-21341: Windows Kernel Remote Code Execution Vulnerability Windows Kernel Remote Code Execution Vulnerability
nvd
CVE-2023-36721P4HIGHCVSS 7.0≥ 10.0.22621.0, < 10.0.22621.24282023-10-10
CVE-2023-36721 [HIGH] CWE-269 CVE-2023-36721: Windows Error Reporting Service Elevation of Privilege Vulnerability Windows Error Reporting Service Elevation of Privilege Vulnerability
nvd
CVE-2024-21429P4MEDIUMCVSS 6.8≥ 10.0.22621.0, < 10.0.22621.32962024-03-12
CVE-2024-21429 [MEDIUM] CWE-197 CVE-2024-21429: Windows USB Hub Driver Remote Code Execution Vulnerability Windows USB Hub Driver Remote Code Execution Vulnerability
nvd
CVE-2023-21771P4HIGHCVSS 7.0≥ 10.0.22621.0, < 10.0.22621.11052023-01-10
CVE-2023-21771 [HIGH] CWE-591 CVE-2023-21771: Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability
nvd
CVE-2022-38021P4HIGHCVSS 7.0≥ 10.0.22621.0, < 10.0.22621.6742022-10-11
CVE-2022-38021 [HIGH] CWE-362 CVE-2022-38021: Connected User Experiences and Telemetry Elevation of Privilege Vulnerability Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
nvd
Microsoft Windows 11 Version 22H2 vulnerabilities | cvebase