Microsoft Windows 11 Version 22H2 vulnerabilities

1,775 known vulnerabilities affecting microsoft/windows_11_version_22h2.

Total CVEs
1,775
CISA KEV
72
actively exploited
Public exploits
32
Exploited in wild
54
Severity breakdown
CRITICAL42HIGH1246MEDIUM479LOW8

Vulnerabilities

Page 89 of 89
CVE-2022-38032MEDIUMCVSS 6.6≥ 10.0.22621.0, < 10.0.22621.6742022-10-11
CVE-2022-38032 [MEDIUM] CVE-2022-38032: Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability
nvd
CVE-2022-37977MEDIUMCVSS 6.5≥ 10.0.22621.0, < 10.0.22621.6742022-10-11
CVE-2022-37977 [MEDIUM] CVE-2022-37977: Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
nvd
CVE-2022-38033MEDIUMCVSS 6.5≥ 10.0.22621.0, < 10.0.22621.6742022-10-11
CVE-2022-38033 [MEDIUM] CVE-2022-38033: Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability
nvd
CVE-2022-38043MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.6742022-10-11
CVE-2022-38043 [MEDIUM] CVE-2022-38043: Windows Security Support Provider Interface Information Disclosure Vulnerability Windows Security Support Provider Interface Information Disclosure Vulnerability
nvd
CVE-2022-35770MEDIUMCVSS 6.5≥ 10.0.22621.0, < 10.0.22621.6742022-10-11
CVE-2022-35770 [MEDIUM] Windows NTLM Spoofing Vulnerability Windows NTLM Spoofing Vulnerability Windows NTLM Spoofing Vulnerability
cvelistv5
CVE-2022-38025MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.6742022-10-11
CVE-2022-38025 [MEDIUM] CVE-2022-38025: Windows Distributed File System (DFS) Information Disclosure Vulnerability Windows Distributed File System (DFS) Information Disclosure Vulnerability
nvd
CVE-2022-37965MEDIUMCVSS 5.9≥ 10.0.22621.0, < 10.0.22621.6742022-10-11
CVE-2022-37965 [MEDIUM] CVE-2022-37965: Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
nvd
CVE-2022-37974MEDIUMCVSS 6.5≥ 10.0.22621.0, < 10.0.22621.6742022-10-11
CVE-2022-37974 [MEDIUM] CVE-2022-37974: Windows Mixed Reality Developer Tools Information Disclosure Vulnerability Windows Mixed Reality Developer Tools Information Disclosure Vulnerability
nvd
CVE-2022-37985MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.6742022-10-11
CVE-2022-37985 [MEDIUM] CVE-2022-37985: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2022-37996MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.6742022-10-11
CVE-2022-37996 [MEDIUM] CVE-2022-37996: Windows Kernel Memory Information Disclosure Vulnerability Windows Kernel Memory Information Disclosure Vulnerability
nvd
CVE-2022-38026MEDIUMCVSS 5.5≥ 10.0.22621.0, < 10.0.22621.6742022-10-11
CVE-2022-38026 [MEDIUM] CVE-2022-38026: Windows DHCP Client Information Disclosure Vulnerability Windows DHCP Client Information Disclosure Vulnerability
nvd
CVE-2022-38022LOWCVSS 3.3≥ 10.0.22621.0, < 10.0.22621.6742022-10-11
CVE-2022-38022 [LOW] CVE-2022-38022: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-23257HIGHCVSS 8.8≥ 10.0.22621.0, < 10.0.22621.14132022-04-15
CVE-2022-23257 [HIGH] CVE-2022-23257: Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2021-34527HIGHCVSS 8.8KEVPoC≥ 10.0.0, < 10.0.22621.6742021-07-02
CVE-2021-34527 [HIGH] CVE-2021-34527: <p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly pe A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. UPDAT
nvd
CVE-2013-3900HIGHCVSS 8.8KEVvN/A2013-12-11
CVE-2013-3900 [HIGH] CWE-347 CVE-2013-3900: Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Upd Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in all currently supported versions of Windows 10 and Windows 11. While the format is different from the original CVE published in 2013, ex
nvd