cbcvebase.

Microsoft Windows 11 Version 22H2 vulnerabilities

1,776 known vulnerabilities affecting microsoft/windows_11_version_22h2.

Total CVEs
1,776
CISA KEV
72
actively exploited
Public exploits
51
Exploited in wild
87
Severity breakdown
CRITICAL42HIGH1247MEDIUM479LOW8

Vulnerabilities

Page 64 of 89
CVE-2024-26243P4HIGHCVSS 7.0≥ 10.0.22621.0, < 10.0.22621.34472024-04-09
CVE-2024-26243 [HIGH] CWE-126 CVE-2024-26243: Windows USB Print Driver Elevation of Privilege Vulnerability Windows USB Print Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-21405P4HIGHCVSS 7.0≥ 10.0.22621.0, < 10.0.22621.31552024-02-13
CVE-2024-21405 [HIGH] CWE-591 CVE-2024-21405: Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
nvd
CVE-2023-35378P4HIGHCVSS 7.0≥ 10.0.22621.0, < 10.0.22621.21342023-08-08
CVE-2023-35378 [HIGH] CWE-367 CVE-2023-35378: Windows Projected File System Elevation of Privilege Vulnerability Windows Projected File System Elevation of Privilege Vulnerability
nvd
CVE-2024-26242P4HIGHCVSS 7.0≥ 10.0.22621.0, < 10.0.22621.34472024-04-09
CVE-2024-26242 [HIGH] CWE-591 CVE-2024-26242: Windows Telephony Server Elevation of Privilege Vulnerability Windows Telephony Server Elevation of Privilege Vulnerability
nvd
CVE-2025-26637P4MEDIUMCVSS 6.8≥ 10.0.22621.0, < 10.0.22621.51892025-04-08
CVE-2025-26637 [MEDIUM] CWE-693 CVE-2025-26637: Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a securi Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2023-24899P4HIGHCVSS 7.0≥ 10.0.22621.0, < 10.0.22621.17022023-05-09
CVE-2023-24899 [HIGH] CWE-591 CVE-2023-24899: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2024-21355P4HIGHCVSS 7.0≥ 10.0.22621.0, < 10.0.22621.31552024-02-13
CVE-2024-21355 [HIGH] CWE-591 CVE-2024-21355: Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
nvd
CVE-2023-32010P4HIGHCVSS 7.0≥ 10.0.22621.0, < 10.0.22621.18482023-06-14
CVE-2023-32010 [HIGH] CWE-591 CVE-2023-32010: Windows Bus Filter Driver Elevation of Privilege Vulnerability Windows Bus Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-28273P4HIGHCVSS 7.0≥ 10.0.22621.0, < 10.0.22621.15552023-04-11
CVE-2023-28273 [HIGH] CWE-591 CVE-2023-28273: Windows Clip Service Elevation of Privilege Vulnerability Windows Clip Service Elevation of Privilege Vulnerability
nvd
CVE-2023-23393P4HIGHCVSS 7.0≥ 10.0.22621.0, < 10.0.22621.14132023-03-14
CVE-2023-23393 [HIGH] CWE-591 CVE-2023-23393: Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability
nvd
CVE-2024-26252P4MEDIUMCVSS 6.8≥ 10.0.22621.0, < 10.0.22621.34472024-04-09
CVE-2024-26252 [MEDIUM] CWE-822 CVE-2024-26252: Windows rndismp6.sys Remote Code Execution Vulnerability Windows rndismp6.sys Remote Code Execution Vulnerability
nvd
CVE-2024-26253P4MEDIUMCVSS 6.8≥ 10.0.22621.0, < 10.0.22621.34472024-04-09
CVE-2024-26253 [MEDIUM] CWE-20 CVE-2024-26253: Windows rndismp6.sys Remote Code Execution Vulnerability Windows rndismp6.sys Remote Code Execution Vulnerability
nvd
CVE-2023-21694P4MEDIUMCVSS 6.8≥ 10.0.22621.0, < 10.0.22621.12652023-02-14
CVE-2023-21694 [MEDIUM] CWE-122 CVE-2023-21694: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2025-49743P4MEDIUMCVSS 6.7≥ 10.0.22621.0, < 10.0.22621.57682025-08-12
CVE-2025-49743 [MEDIUM] CWE-362 CVE-2025-49743: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54915P4MEDIUMCVSS 6.7≥ 10.0.22621.0, < 10.0.22621.59092025-09-09
CVE-2025-54915 [MEDIUM] CWE-843 CVE-2025-54915: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53810P4MEDIUMCVSS 6.7≥ 10.0.22621.0, < 10.0.22621.59092025-09-09
CVE-2025-53810 [MEDIUM] CWE-843 CVE-2025-53810: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54109P4MEDIUMCVSS 6.7≥ 10.0.22621.0, < 10.0.22621.59092025-09-09
CVE-2025-54109 [MEDIUM] CWE-843 CVE-2025-54109: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53808P4MEDIUMCVSS 6.7≥ 10.0.22621.0, < 10.0.22621.59092025-09-09
CVE-2025-53808 [MEDIUM] CWE-843 CVE-2025-53808: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54094P4MEDIUMCVSS 6.7≥ 10.0.22621.0, < 10.0.22621.59092025-09-09
CVE-2025-54094 [MEDIUM] CWE-843 CVE-2025-54094: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-48823P4MEDIUMCVSS 5.9≥ 10.0.22621.0, < 10.0.22621.56242025-07-08
CVE-2025-48823 [MEDIUM] CWE-310 CVE-2025-48823: Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose i Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a network.
nvd
Microsoft Windows 11 Version 22H2 vulnerabilities | cvebase