cbcvebase.

Microsoft Windows Server 2022 vulnerabilities

3,303 known vulnerabilities affecting microsoft/windows_server_2022.

Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
136
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14

Vulnerabilities

Page 100 of 166
CVE-2024-26227P3MEDIUMCVSS 6.6fixed in 10.0.20348.2402≥ 10.0.20348.0, < 10.0.20348.24022024-04-09
CVE-2024-26227 [MEDIUM] CWE-416 CVE-2024-26227: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2026-24285P3HIGHCVSS 7.0fixed in 10.0.20348.4830≥ 10.0.20348.0, < 10.0.20348.48932026-03-10
CVE-2026-24285 [HIGH] CWE-416 CVE-2026-24285: Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20842P3HIGHCVSS 7.0fixed in 10.0.20348.4648≥ 10.0.20348.0, < 10.0.20348.46482026-01-13
CVE-2026-20842 [HIGH] CWE-416 CVE-2026-20842: Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32073P3HIGHCVSS 7.0fixed in 10.0.20348.5020≥ 10.0.20348.0, < 10.0.20348.50202026-04-14
CVE-2026-32073 [HIGH] CWE-416 CVE-2026-32073: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-60716P3HIGHCVSS 7.0fixed in 10.0.20348.4346≥ 10.0.20348.0, < 10.0.20348.44052025-11-11
CVE-2025-60716 [HIGH] CWE-416 CVE-2025-60716: Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21242P3HIGHCVSS 7.0fixed in 10.0.20348.4711≥ 10.0.20348.0, < 10.0.20348.47732026-02-10
CVE-2026-21242 [HIGH] CWE-416 CVE-2026-21242: Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges lo Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-25170P3HIGHCVSS 7.0fixed in 10.0.20348.4830≥ 10.0.20348.0, < 10.0.20348.48932026-03-10
CVE-2026-25170 [HIGH] CWE-416 CVE-2026-25170: Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally. Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32075P3HIGHCVSS 7.0fixed in 10.0.20348.5020≥ 10.0.20348.0, < 10.0.20348.50202026-04-14
CVE-2026-32075 [HIGH] CWE-416 CVE-2026-32075: Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker t Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34347P3HIGHCVSS 7.0fixed in 10.0.20348.5074≥ 10.0.20348.0, < 10.0.20348.51392026-05-12
CVE-2026-34347 [HIGH] CWE-416 CVE-2026-34347: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42984P3HIGHCVSS 7.0fixed in 10.0.20348.5256≥ 10.0.20348.0, < 10.0.20348.52562026-06-09
CVE-2026-42984 [HIGH] CWE-416 CVE-2026-42984: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56173P3HIGHCVSS 7.0fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-56173 [HIGH] CWE-416 CVE-2026-56173: Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58629P3HIGHCVSS 7.0fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-58629 [HIGH] CWE-416 CVE-2026-58629: Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50397P3HIGHCVSS 7.0fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-50397 [HIGH] CWE-416 CVE-2026-50397: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50166P3MEDIUMCVSS 6.5fixed in 10.0.20348.3989≥ 10.0.20348.0, < 10.0.20348.40522025-08-12
CVE-2025-50166 [MEDIUM] CWE-190 CVE-2025-50166: Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized a Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized attacker to disclose information over a network.
nvd
CVE-2025-59185P3MEDIUMCVSS 6.5fixed in 10.0.20348.4294≥ 10.0.20348.0, < 10.0.20348.42942025-10-14
CVE-2025-59185 [MEDIUM] CWE-73 CVE-2025-59185: External control of file name or path in Windows Core Shell allows an unauthorized attacker to perfo External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-56186P3MEDIUMCVSS 6.5fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-56186 [MEDIUM] CWE-125 CVE-2026-56186: Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-50376P3MEDIUMCVSS 6.5fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-50376 [MEDIUM] CWE-908 CVE-2026-50376: Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-59244P3MEDIUMCVSS 6.5fixed in 10.0.20348.4294≥ 10.0.20348.0, < 10.0.20348.42942025-10-14
CVE-2025-59244 [MEDIUM] CWE-73 CVE-2025-59244: External control of file name or path in Windows Core Shell allows an unauthorized attacker to perfo External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-32151P3MEDIUMCVSS 6.5fixed in 10.0.20348.5020≥ 10.0.20348.0, < 10.0.20348.50202026-04-14
CVE-2026-32151 [MEDIUM] CWE-200 CVE-2026-32151: Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized att Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-50432P3MEDIUMCVSS 6.5fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-50432 [MEDIUM] CWE-416 CVE-2026-50432: Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny ser Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.
nvd
Microsoft Windows Server 2022 vulnerabilities | cvebase