cbcvebase.

Microsoft Windows 11 Version 22H2 vulnerabilities

1,776 known vulnerabilities affecting microsoft/windows_11_version_22h2.

Total CVEs
1,776
CISA KEV
72
actively exploited
Public exploits
51
Exploited in wild
87
Severity breakdown
CRITICAL42HIGH1247MEDIUM479LOW8

Vulnerabilities

Page 8 of 89
CVE-2023-36005P3HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.28612023-12-12
CVE-2023-36005 [HIGH] CWE-591 CVE-2023-36005: Windows Telephony Server Elevation of Privilege Vulnerability Windows Telephony Server Elevation of Privilege Vulnerability
nvd
CVE-2023-21746HIGHCVSS 7.8ExploitedPoC≥ 10.0.22621.0, < 10.0.22621.11052023-01-10
CVE-2023-21746 [HIGH] Windows NTLM Elevation of Privilege Vulnerability Windows NTLM Elevation of Privilege Vulnerability Windows NTLM Elevation of Privilege Vulnerability
cvelistv5
CVE-2025-49677P3HIGHCVSS 7.0PoC≥ 10.0.22621.0, < 10.0.22621.56242025-07-08
CVE-2025-49677 [HIGH] CWE-416 CVE-2025-49677: Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privilege Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-33064P2HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.54722025-06-10
CVE-2025-33064 [HIGH] CWE-122 CVE-2025-33064: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
nvd
CVE-2023-32015P2CRITICALCVSS 9.8≥ 10.0.22621.0, < 10.0.22621.18482023-06-14
CVE-2023-32015 [CRITICAL] CWE-20 CVE-2023-32015: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-28250P2CRITICALCVSS 9.8≥ 10.0.22621.0, < 10.0.22621.15552023-04-11
CVE-2023-28250 [CRITICAL] CWE-191 CVE-2023-28250: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-29363P2CRITICALCVSS 9.8≥ 10.0.22621.0, < 10.0.22621.18482023-06-14
CVE-2023-29363 [CRITICAL] CWE-122 CVE-2023-29363: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-32014P2CRITICALCVSS 9.8≥ 10.0.22621.0, < 10.0.22621.18482023-06-14
CVE-2023-32014 [CRITICAL] CWE-191 CVE-2023-32014: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-35365P2CRITICALCVSS 9.8≥ 10.0.22621.0, < 10.0.22621.19922023-07-11
CVE-2023-35365 [CRITICAL] CWE-20 CVE-2023-35365: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2023-35366P2CRITICALCVSS 9.8≥ 10.0.22621.0, < 10.0.22621.19922023-07-11
CVE-2023-35366 [CRITICAL] CWE-20 CVE-2023-35366: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2023-35367P2CRITICALCVSS 9.8≥ 10.0.22621.0, < 10.0.22621.19922023-07-11
CVE-2023-35367 [CRITICAL] CWE-20 CVE-2023-35367: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2023-23392P2CRITICALCVSS 9.8≥ 10.0.22621.0, < 10.0.22621.14132023-03-14
CVE-2023-23392 [CRITICAL] CWE-416 CVE-2023-23392: HTTP Protocol Stack Remote Code Execution Vulnerability HTTP Protocol Stack Remote Code Execution Vulnerability
nvd
CVE-2023-36911P2CRITICALCVSS 9.8≥ 10.0.22621.0, < 10.0.22621.21342023-08-08
CVE-2023-36911 [CRITICAL] CWE-190 CVE-2023-36911: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2025-26670P2HIGHCVSS 8.1≥ 10.0.22621.0, < 10.0.22621.51892025-04-08
CVE-2025-26670 [HIGH] CWE-416 CVE-2025-26670: Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attack Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
nvd
CVE-2022-44666P3HIGHCVSS 7.8≥ 10.0.22621.0, < 10.0.22621.9932022-12-13
CVE-2022-44666 [HIGH] CVE-2022-44666: Windows Contacts Remote Code Execution Vulnerability Windows Contacts Remote Code Execution Vulnerability
nvd
CVE-2023-21752P3HIGHCVSS 7.1PoC≥ 10.0.22621.0, < 10.0.22621.11052023-01-10
CVE-2023-21752 [HIGH] CWE-284 CVE-2023-21752: Windows Backup Service Elevation of Privilege Vulnerability Windows Backup Service Elevation of Privilege Vulnerability
nvd
CVE-2023-36606P3HIGHCVSS 7.5≥ 10.0.22621.0, < 10.0.22621.24282023-10-10
CVE-2023-36606 [HIGH] CWE-400 CVE-2023-36606: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2024-30017P2HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.35932024-05-14
CVE-2024-30017 [HIGH] CWE-122 CVE-2024-30017: Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2024-38104P2HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.38802024-07-09
CVE-2024-38104 [HIGH] CWE-822 CVE-2024-38104: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2024-38116P2HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.40372024-08-13
CVE-2024-38116 [HIGH] CWE-122 CVE-2024-38116: Windows IP Routing Management Snapin Remote Code Execution Vulnerability Windows IP Routing Management Snapin Remote Code Execution Vulnerability
nvd
Microsoft Windows 11 Version 22H2 vulnerabilities | cvebase