Microsoft Windows Server 2022 vulnerabilities
3,303 known vulnerabilities affecting microsoft/windows_server_2022.
Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
136
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14
Vulnerabilities
Page 102 of 166
CVE-2023-36004P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.21592023-12-12
CVE-2023-36004 [HIGH] CWE-287 CVE-2023-36004: Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability
Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability
nvd
CVE-2021-43239P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.20348.4052021-12-15
CVE-2021-43239 [HIGH] CVE-2021-43239: Windows Recovery Environment Agent Elevation of Privilege Vulnerability
Windows Recovery Environment Agent Elevation of Privilege Vulnerability
nvd
CVE-2021-43248P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.20348.4052021-12-15
CVE-2021-43248 [HIGH] CVE-2021-43248: Windows Digital Media Receiver Elevation of Privilege Vulnerability
Windows Digital Media Receiver Elevation of Privilege Vulnerability
nvd
CVE-2022-41095P3HIGHCVSS 7.8≥ 10.0.20348.0, < 10.0.20348.12492022-11-09
CVE-2022-41095 [HIGH] CVE-2022-41095: Windows Digital Media Receiver Elevation of Privilege Vulnerability
Windows Digital Media Receiver Elevation of Privilege Vulnerability
nvd
CVE-2021-38671P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.20348.2302021-09-15
CVE-2021-38671 [HIGH] CWE-269 CVE-2021-38671: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2021-38667P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.20348.2302021-09-15
CVE-2021-38667 [HIGH] CWE-269 CVE-2021-38667: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2021-36973P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.20348.2302021-09-15
CVE-2021-36973 [HIGH] CWE-269 CVE-2021-36973: Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability
Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability
nvd
CVE-2021-38630P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.20348.2302021-09-15
CVE-2021-38630 [HIGH] CWE-269 CVE-2021-38630: Windows Event Tracing Elevation of Privilege Vulnerability
Windows Event Tracing Elevation of Privilege Vulnerability
nvd
CVE-2021-36964P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.20348.2302021-09-15
CVE-2021-36964 [HIGH] CWE-269 CVE-2021-36964: Windows Event Tracing Elevation of Privilege Vulnerability
Windows Event Tracing Elevation of Privilege Vulnerability
nvd
CVE-2021-41339P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.20348.2882021-10-13
CVE-2021-41339 [HIGH] CWE-269 CVE-2021-41339: Microsoft DWM Core Library Elevation of Privilege Vulnerability
Microsoft DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2021-36957P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.20348.3502021-11-10
CVE-2021-36957 [HIGH] CWE-269 CVE-2021-36957: Windows Desktop Bridge Elevation of Privilege Vulnerability
Windows Desktop Bridge Elevation of Privilege Vulnerability
nvd
CVE-2021-41334P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.20348.2882021-10-13
CVE-2021-41334 [HIGH] CWE-269 CVE-2021-41334: Windows Desktop Bridge Elevation of Privilege Vulnerability
Windows Desktop Bridge Elevation of Privilege Vulnerability
nvd
CVE-2025-21331P3HIGHCVSS 7.3fixed in 10.0.20348.3091≥ 10.0.20348.0, < 10.0.20348.30912025-01-14
CVE-2025-21331 [HIGH] CWE-59 CVE-2025-21331: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2023-21820P3HIGHCVSS 7.4≥ 10.0.20348.0, < 10.0.20348.15472023-02-14
CVE-2023-21820 [HIGH] CWE-126 CVE-2023-21820: Windows Distributed File System (DFS) Remote Code Execution Vulnerability
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
nvd
CVE-2022-35757P3HIGHCVSS 7.3≥ 10.0.20348.0, < 10.0.20348.8872023-05-31
CVE-2022-35757 [HIGH] CVE-2022-35757: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-32021P3HIGHCVSS 7.1≥ 10.0.20348.0, < 10.0.20348.17872023-06-14
CVE-2023-32021 [HIGH] CVE-2023-32021: Windows SMB Witness Service Security Feature Bypass Vulnerability
Windows SMB Witness Service Security Feature Bypass Vulnerability
nvd
CVE-2026-40413P3HIGHCVSS 7.4fixed in 10.0.20348.5074≥ 10.0.20348.0, < 10.0.20348.51392026-05-12
CVE-2026-40413 [HIGH] CWE-476 CVE-2026-40413: Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an a
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an adjacent network.
cvelistv5nvd
CVE-2022-26818P3MEDIUMCVSS 6.6≥ 10.0.20348.0, < 10.0.20348.6432022-04-15
CVE-2022-26818 [MEDIUM] CVE-2022-26818: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2022-26829P3MEDIUMCVSS 6.6≥ 10.0.20348.0, < 10.0.20348.6432022-04-15
CVE-2022-26829 [MEDIUM] CWE-362 CVE-2022-26829: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2022-26821P3MEDIUMCVSS 6.6≥ 10.0.20348.0, < 10.0.20348.6432022-04-15
CVE-2022-26821 [MEDIUM] CWE-362 CVE-2022-26821: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd