Microsoft Windows 11 Version 22H2 vulnerabilities
1,776 known vulnerabilities affecting microsoft/windows_11_version_22h2.
Total CVEs
1,776
CISA KEV
72
actively exploited
Public exploits
51
Exploited in wild
87
Severity breakdown
CRITICAL42HIGH1247MEDIUM479LOW8
Vulnerabilities
Page 70 of 89
CVE-2025-21261P4MEDIUMCVSS 6.6≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21261 [MEDIUM] CWE-125 CVE-2025-21261: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21341P4MEDIUMCVSS 6.6≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21341 [MEDIUM] CWE-125 CVE-2025-21341: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2023-24944P4MEDIUMCVSS 6.5≥ 10.0.22621.0, < 10.0.22621.17022023-05-09
CVE-2023-24944 [MEDIUM] CWE-843 CVE-2023-24944: Windows Bluetooth Driver Information Disclosure Vulnerability
Windows Bluetooth Driver Information Disclosure Vulnerability
nvd
CVE-2023-32037P4MEDIUMCVSS 6.5≥ 10.0.22621.0, < 10.0.22621.19922023-07-11
CVE-2023-32037 [MEDIUM] CWE-20 CVE-2023-32037: Windows Layer-2 Bridge Network Driver Information Disclosure Vulnerability
Windows Layer-2 Bridge Network Driver Information Disclosure Vulnerability
nvd
CVE-2022-41086P4MEDIUMCVSS 6.4≥ 10.0.22621.0, < 10.0.22621.8192022-11-09
CVE-2022-41086 [MEDIUM] CWE-362 CVE-2022-41086: Windows Group Policy Elevation of Privilege Vulnerability
Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2024-38264P4MEDIUMCVSS 5.9≥ 10.0.22621.0, < 10.0.22621.44602024-11-12
CVE-2024-38264 [MEDIUM] CWE-591 CVE-2024-38264: Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability
Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability
nvd
CVE-2023-21693P4MEDIUMCVSS 5.7≥ 10.0.22621.0, < 10.0.22621.12652023-02-14
CVE-2023-21693 [MEDIUM] CWE-125 CVE-2023-21693: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2024-20692P4MEDIUMCVSS 5.7≥ 10.0.22621.0, < 10.0.22621.30072024-01-09
CVE-2024-20692 [MEDIUM] CWE-326 CVE-2024-20692: Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
nvd
CVE-2024-43547P4MEDIUMCVSS 5.9≥ 10.0.22621.0, < 10.0.22621.43172024-10-08
CVE-2024-43547 [MEDIUM] CWE-325 CVE-2024-43547: Windows Kerberos Information Disclosure Vulnerability
Windows Kerberos Information Disclosure Vulnerability
nvd
CVE-2025-21269P4MEDIUMCVSS 4.3≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21269 [MEDIUM] CWE-41 CVE-2025-21269: Windows HTML Platforms Security Feature Bypass Vulnerability
Windows HTML Platforms Security Feature Bypass Vulnerability
nvd
CVE-2025-55338P4MEDIUMCVSS 4.6≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-55338 [MEDIUM] CWE-1310 CVE-2025-55338: Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a s
Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2023-35336P4MEDIUMCVSS 5.4≥ 10.0.22621.0, < 10.0.22621.19922023-07-11
CVE-2023-35336 [MEDIUM] CWE-20 CVE-2023-35336: Windows MSHTML Platform Security Feature Bypass Vulnerability
Windows MSHTML Platform Security Feature Bypass Vulnerability
nvd
CVE-2025-29837P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.53352025-05-13
CVE-2025-29837 [MEDIUM] CWE-59 CVE-2025-29837: Improper link resolution before file access ('link following') in Windows Installer allows an author
Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally.
nvd
CVE-2023-36889P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.21342023-08-08
CVE-2023-36889 [MEDIUM] CWE-284 CVE-2023-36889: Windows Group Policy Security Feature Bypass Vulnerability
Windows Group Policy Security Feature Bypass Vulnerability
nvd
CVE-2025-59211P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-59211 [MEDIUM] CWE-200 CVE-2025-59211: Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
nvd
CVE-2025-55336P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-55336 [MEDIUM] CWE-200 CVE-2025-55336: Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver
Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2025-62209P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.60602025-11-11
CVE-2025-62209 [MEDIUM] CWE-532 CVE-2025-62209: Insertion of sensitive information into log file in Windows License Manager allows an authorized att
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
nvd
CVE-2025-62208P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.60602025-11-11
CVE-2025-62208 [MEDIUM] CWE-532 CVE-2025-62208: Insertion of sensitive information into log file in Windows License Manager allows an authorized att
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
nvd
CVE-2025-24068P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.54722025-06-10
CVE-2025-24068 [MEDIUM] CWE-126 CVE-2025-24068: Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose in
Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-49684P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.56242025-07-08
CVE-2025-49684 [MEDIUM] CWE-126 CVE-2025-49684: Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locall
Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally.
nvd