cbcvebase.

Microsoft Windows 11 Version 22H2 vulnerabilities

1,776 known vulnerabilities affecting microsoft/windows_11_version_22h2.

Total CVEs
1,776
CISA KEV
72
actively exploited
Public exploits
51
Exploited in wild
87
Severity breakdown
CRITICAL42HIGH1247MEDIUM479LOW8

Vulnerabilities

Page 75 of 89
CVE-2023-36724P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.24282023-10-10
CVE-2023-36724 [MEDIUM] CWE-287 CVE-2023-36724: Windows Power Management Service Information Disclosure Vulnerability Windows Power Management Service Information Disclosure Vulnerability
nvd
CVE-2025-59190P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-59190 [MEDIUM] CWE-20 CVE-2025-59190: Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to d Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.
nvd
CVE-2023-23394P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.14132023-03-14
CVE-2023-23394 [MEDIUM] CWE-822 CVE-2023-23394: Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
nvd
CVE-2023-23409P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.14132023-03-14
CVE-2023-23409 [MEDIUM] CWE-20 CVE-2023-23409: Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
nvd
CVE-2025-26644P4MEDIUMCVSS 5.1≥ 10.0.22621.0, < 10.0.22621.51892025-04-08
CVE-2025-26644 [MEDIUM] CWE-1039 CVE-2025-26644: Automated recognition mechanism with inadequate detection or handling of adversarial input perturbat Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.
nvd
CVE-2024-21305P4MEDIUMCVSS 4.4≥ 10.0.22621.0, < 10.0.22621.30072024-01-09
CVE-2024-21305 [MEDIUM] CWE-732 CVE-2024-21305: Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
nvd
CVE-2025-21328P4MEDIUMCVSS 4.3≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21328 [MEDIUM] CWE-41 CVE-2025-21328: MapUrlToZone Security Feature Bypass Vulnerability MapUrlToZone Security Feature Bypass Vulnerability
nvd
CVE-2025-21329P4MEDIUMCVSS 4.3≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21329 [MEDIUM] CWE-41 CVE-2025-21329: MapUrlToZone Security Feature Bypass Vulnerability MapUrlToZone Security Feature Bypass Vulnerability
nvd
CVE-2025-55332P4MEDIUMCVSS 4.6≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-55332 [MEDIUM] CWE-841 CVE-2025-55332: Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-55330P4MEDIUMCVSS 4.6≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-55330 [MEDIUM] CWE-841 CVE-2025-55330: Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-21254P4MEDIUMCVSS 6.5≥ 10.0.22621.0, < 10.0.22621.48902025-02-11
CVE-2025-21254 [MEDIUM] CWE-125 CVE-2025-21254: Internet Connection Sharing (ICS) Denial of Service Vulnerability Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd
CVE-2025-21352P4MEDIUMCVSS 6.5≥ 10.0.22621.0, < 10.0.22621.48902025-02-11
CVE-2025-21352 [MEDIUM] CWE-400 CVE-2025-21352: Internet Connection Sharing (ICS) Denial of Service Vulnerability Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd
CVE-2025-21212P4MEDIUMCVSS 6.5≥ 10.0.22621.0, < 10.0.22621.48902025-02-11
CVE-2025-21212 [MEDIUM] CWE-125 CVE-2025-21212: Internet Connection Sharing (ICS) Denial of Service Vulnerability Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd
CVE-2025-21216P4MEDIUMCVSS 6.5≥ 10.0.22621.0, < 10.0.22621.48902025-02-11
CVE-2025-21216 [MEDIUM] CWE-125 CVE-2025-21216: Internet Connection Sharing (ICS) Denial of Service Vulnerability Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd
CVE-2024-38048P4MEDIUMCVSS 6.5≥ 10.0.22621.0, < 10.0.22621.38802024-07-09
CVE-2024-38048 [MEDIUM] CWE-125 CVE-2024-38048: Windows Network Driver Interface Specification (NDIS) Denial of Service Vulnerability Windows Network Driver Interface Specification (NDIS) Denial of Service Vulnerability
nvd
CVE-2024-38105P4MEDIUMCVSS 6.5≥ 10.0.22621.0, < 10.0.22621.38802024-07-09
CVE-2024-38105 [MEDIUM] CWE-20 CVE-2024-38105: Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
nvd
CVE-2024-38101P4MEDIUMCVSS 6.5≥ 10.0.22621.0, < 10.0.22621.38802024-07-09
CVE-2024-38101 [MEDIUM] CWE-125 CVE-2024-38101: Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
nvd
CVE-2024-38102P4MEDIUMCVSS 6.5≥ 10.0.22621.0, < 10.0.22621.38802024-07-09
CVE-2024-38102 [MEDIUM] CWE-125 CVE-2024-38102: Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
nvd
CVE-2024-30038HIGHCVSS 7.8PoC≥ 10.0.22621.0, < 10.0.22621.35932024-05-14
CVE-2024-30038 [HIGH] CWE-122 Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability
cvelistv5
CVE-2023-38160P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.22832023-09-12
CVE-2023-38160 [MEDIUM] CWE-416 CVE-2023-38160: Windows TCP/IP Information Disclosure Vulnerability Windows TCP/IP Information Disclosure Vulnerability
nvd
Microsoft Windows 11 Version 22H2 vulnerabilities | cvebase