Microsoft Windows 11 Version 22H2 vulnerabilities
1,776 known vulnerabilities affecting microsoft/windows_11_version_22h2.
Total CVEs
1,776
CISA KEV
72
actively exploited
Public exploits
51
Exploited in wild
87
Severity breakdown
CRITICAL42HIGH1247MEDIUM479LOW8
Vulnerabilities
Page 76 of 89
CVE-2024-38055P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.38802024-07-09
CVE-2024-38055 [MEDIUM] CWE-20 CVE-2024-38055: Microsoft Windows Codecs Library Information Disclosure Vulnerability
Microsoft Windows Codecs Library Information Disclosure Vulnerability
nvd
CVE-2023-36428P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.27152023-11-14
CVE-2023-36428 [MEDIUM] CWE-125 CVE-2023-36428: Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
nvd
CVE-2025-21257P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.47512025-01-14
CVE-2025-21257 [MEDIUM] CWE-125 CVE-2025-21257: Windows WLAN AutoConfig Service Information Disclosure Vulnerability
Windows WLAN AutoConfig Service Information Disclosure Vulnerability
nvd
CVE-2022-38043P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.6742022-10-11
CVE-2022-38043 [MEDIUM] CVE-2022-38043: Windows Security Support Provider Interface Information Disclosure Vulnerability
Windows Security Support Provider Interface Information Disclosure Vulnerability
nvd
CVE-2022-37996P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.6742022-10-11
CVE-2022-37996 [MEDIUM] CVE-2022-37996: Windows Kernel Memory Information Disclosure Vulnerability
Windows Kernel Memory Information Disclosure Vulnerability
nvd
CVE-2024-43500P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.43172024-10-08
CVE-2024-43500 [MEDIUM] CWE-126 CVE-2024-43500: Windows Resilient File System (ReFS) Information Disclosure Vulnerability
Windows Resilient File System (ReFS) Information Disclosure Vulnerability
nvd
CVE-2022-44674P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.9932022-12-13
CVE-2022-44674 [MEDIUM] CVE-2022-44674: Windows Bluetooth Driver Information Disclosure Vulnerability
Windows Bluetooth Driver Information Disclosure Vulnerability
nvd
CVE-2023-32039P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.19922023-07-11
CVE-2023-32039 [MEDIUM] CWE-125 CVE-2023-32039: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-32085P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.19922023-07-11
CVE-2023-32085 [MEDIUM] CWE-126 CVE-2023-32085: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-32040P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.19922023-07-11
CVE-2023-32040 [MEDIUM] CWE-822 CVE-2023-32040: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-35324P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.19922023-07-11
CVE-2023-35324 [MEDIUM] CWE-126 CVE-2023-35324: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-35306P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.19922023-07-11
CVE-2023-35306 [MEDIUM] CWE-20 CVE-2023-35306: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-35341P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.19922023-07-11
CVE-2023-35341 [MEDIUM] CWE-190 CVE-2023-35341: Microsoft DirectMusic Information Disclosure Vulnerability
Microsoft DirectMusic Information Disclosure Vulnerability
nvd
CVE-2025-59190P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-59190 [MEDIUM] CWE-20 CVE-2025-59190: Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to d
Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.
nvd
CVE-2023-23394P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.14132023-03-14
CVE-2023-23394 [MEDIUM] CWE-822 CVE-2023-23394: Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
nvd
CVE-2023-23409P4MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.14132023-03-14
CVE-2023-23409 [MEDIUM] CWE-20 CVE-2023-23409: Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
nvd
CVE-2025-55332P4MEDIUMCVSS 4.6≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-55332 [MEDIUM] CWE-841 CVE-2025-55332: Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-55330P4MEDIUMCVSS 4.6≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-55330 [MEDIUM] CWE-841 CVE-2025-55330: Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-58717P4MEDIUMCVSS 4.3≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-58717 [MEDIUM] CWE-125 CVE-2025-58717: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-55700P4MEDIUMCVSS 4.3≥ 10.0.22621.0, < 10.0.22621.60602025-10-14
CVE-2025-55700 [MEDIUM] CWE-125 CVE-2025-55700: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd