Microsoft Windows 11 Version 22H3 vulnerabilities
1,502 known vulnerabilities affecting microsoft/windows_11_version_22h3.
Total CVEs
1,502
CISA KEV
57
actively exploited
Public exploits
24
Exploited in wild
30
Severity breakdown
CRITICAL18HIGH1048MEDIUM429LOW7
Vulnerabilities
Page 13 of 76
CVE-2026-20823MEDIUMCVSS 5.5≥ 10.0.22631.0, < 10.0.22631.64912026-01-13
CVE-2026-20823 [MEDIUM] CWE-200 CVE-2026-20823: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
cvelistv5nvd
CVE-2026-20819MEDIUMCVSS 5.5≥ 10.0.22631.0, < 10.0.22631.64912026-01-13
CVE-2026-20819 [MEDIUM] CWE-822 CVE-2026-20819: Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an autho
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.
cvelistv5nvd
CVE-2026-20839MEDIUMCVSS 5.5≥ 10.0.22631.0, < 10.0.22631.64912026-01-13
CVE-2026-20839 [MEDIUM] CWE-284 CVE-2026-20839: Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker t
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.
cvelistv5nvd
CVE-2026-20838MEDIUMCVSS 5.5≥ 10.0.22631.0, < 10.0.22631.64912026-01-13
CVE-2026-20838 [MEDIUM] CWE-209 CVE-2026-20838: Generation of error message containing sensitive information in Windows Kernel allows an authorized
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.
cvelistv5nvd
CVE-2026-20824MEDIUMCVSS 5.5≥ 10.0.22631.0, < 10.0.22631.64912026-01-13
CVE-2026-20824 [MEDIUM] CWE-693 CVE-2026-20824: Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass
Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.
cvelistv5nvd
CVE-2026-20939MEDIUMCVSS 5.5≥ 10.0.22631.0, < 10.0.22631.64912026-01-13
CVE-2026-20939 [MEDIUM] CWE-200 CVE-2026-20939: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
cvelistv5nvd
CVE-2026-20847MEDIUMCVSS 6.5≥ 10.0.22631.0, < 10.0.22631.64912026-01-13
CVE-2026-20847 [MEDIUM] CWE-200 CVE-2026-20847: Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized att
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.
cvelistv5nvd
CVE-2026-20829MEDIUMCVSS 5.5≥ 10.0.22631.0, < 10.0.22631.64912026-01-13
CVE-2026-20829 [MEDIUM] CWE-125 CVE-2026-20829: Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.
cvelistv5nvd
CVE-2026-20962MEDIUMCVSS 4.4≥ 10.0.22631.0, < 10.0.22631.64912026-01-13
CVE-2026-20962 [MEDIUM] CWE-908 CVE-2026-20962: Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized a
Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally.
cvelistv5nvd
CVE-2026-20872MEDIUMCVSS 6.5≥ 10.0.22631.0, < 10.0.22631.64912026-01-13
CVE-2026-20872 [MEDIUM] CWE-73 CVE-2026-20872: External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spo
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
cvelistv5nvd
CVE-2026-20812MEDIUMCVSS 6.5≥ 10.0.22631.0, < 10.0.22631.64912026-01-13
CVE-2026-20812 [MEDIUM] CWE-20 CVE-2026-20812: Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authoriz
Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network.
cvelistv5nvd
CVE-2026-20936MEDIUMCVSS 4.3≥ 10.0.22631.0, < 10.0.22631.64912026-01-13
CVE-2026-20936 [MEDIUM] CWE-125 CVE-2026-20936: Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a phys
Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.
cvelistv5nvd
CVE-2026-20935MEDIUMCVSS 6.2≥ 10.0.22631.0, < 10.0.22631.64912026-01-13
CVE-2026-20935 [MEDIUM] CWE-822 CVE-2026-20935: Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unaut
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally.
cvelistv5nvd
CVE-2026-20827MEDIUMCVSS 5.5≥ 10.0.22631.0, < 10.0.22631.64912026-01-13
CVE-2026-20827 [MEDIUM] CWE-200 CVE-2026-20827: Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI)
Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally.
cvelistv5nvd
CVE-2026-20927MEDIUMCVSS 5.3≥ 10.0.22631.0, < 10.0.22631.64912026-01-13
CVE-2026-20927 [MEDIUM] CWE-362 CVE-2026-20927: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service over a network.
cvelistv5nvd
CVE-2026-20876MEDIUMCVSS 6.7≥ 10.0.22631.0, < 10.0.22631.64912026-01-13
CVE-2026-20876 [MEDIUM] CWE-122 CVE-2026-20876: Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authoriz
Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2026-20828MEDIUMCVSS 4.6≥ 10.0.22631.0, < 10.0.22631.64912026-01-13
CVE-2026-20828 [MEDIUM] CWE-125 CVE-2026-20828: Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to d
Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack.
cvelistv5nvd
CVE-2025-62458HIGHCVSS 7.8≥ 10.0.22631.0, < 10.0.22631.63452025-12-09
CVE-2025-62458 [HIGH] CWE-122 CVE-2025-62458: Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privile
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-62571HIGHCVSS 7.8≥ 10.0.22631.0, < 10.0.22631.63452025-12-09
CVE-2025-62571 [HIGH] CWE-20 CVE-2025-62571: Improper input validation in Windows Installer allows an authorized attacker to elevate privileges l
Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-59516HIGHCVSS 7.8≥ 10.0.22631.0, < 10.0.22631.63452025-12-09
CVE-2025-59516 [HIGH] CWE-73 CVE-2025-59516: Missing authentication for critical function in Windows Storage VSP Driver allows an authorized atta
Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
cvelistv5nvd