Microsoft Windows Server 2022 vulnerabilities
3,303 known vulnerabilities affecting microsoft/windows_server_2022.
Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
136
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14
Vulnerabilities
Page 112 of 166
CVE-2026-42903P3MEDIUMCVSS 6.5fixed in 10.0.20348.5256≥ 10.0.20348.0, < 10.0.20348.52562026-06-09
CVE-2026-42903 [MEDIUM] CWE-476 CVE-2026-42903: Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a ne
Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.
nvd
CVE-2022-21883P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.4692022-01-11
CVE-2022-21883 [HIGH] CVE-2022-21883: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2026-26155P3MEDIUMCVSS 6.5fixed in 10.0.20348.5020≥ 10.0.20348.0, < 10.0.20348.50202026-04-14
CVE-2026-26155 [MEDIUM] CWE-126 CVE-2026-26155: Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
nvd
CVE-2026-49799P3MEDIUMCVSS 6.5fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-49799 [MEDIUM] CWE-400 CVE-2026-49799: Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allo
Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.
nvd
CVE-2022-21848P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.4692022-01-11
CVE-2022-21848 [HIGH] CVE-2022-21848: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2021-43219P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.20348.4052021-12-15
CVE-2021-43219 [HIGH] CVE-2021-43219: DirectX Graphics Kernel File Denial of Service Vulnerability
DirectX Graphics Kernel File Denial of Service Vulnerability
nvd
CVE-2022-34724P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.10062022-09-13
CVE-2022-34724 [HIGH] CVE-2022-34724: Windows DNS Server Denial of Service Vulnerability
Windows DNS Server Denial of Service Vulnerability
nvd
CVE-2022-34720P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.10062022-09-13
CVE-2022-34720 [HIGH] CVE-2022-34720: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2022-26915P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.6432022-04-15
CVE-2022-26915 [HIGH] CVE-2022-26915: Windows Secure Channel Denial of Service Vulnerability
Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2022-30202P3HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.8252022-07-12
CVE-2022-30202 [HIGH] CVE-2022-30202: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
nvd
CVE-2024-20661P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.22272024-01-09
CVE-2024-20661 [HIGH] CWE-476 CVE-2024-20661: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2022-30152P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.7702022-06-15
CVE-2022-30152 [HIGH] CVE-2022-30152: Windows Network Address Translation (NAT) Denial of Service Vulnerability
Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2023-36707P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.20312023-10-10
CVE-2023-36707 [HIGH] CWE-20 CVE-2023-36707: Windows Deployment Services Denial of Service Vulnerability
Windows Deployment Services Denial of Service Vulnerability
nvd
CVE-2024-30083P3HIGHCVSS 7.5fixed in 10.0.20348.2522≥ 10.0.20348.0, < 10.0.20348.25272024-06-11
CVE-2024-30083 [HIGH] CWE-121 CVE-2024-30083: Windows Standards-Based Storage Management Service Denial of Service Vulnerability
Windows Standards-Based Storage Management Service Denial of Service Vulnerability
nvd
CVE-2023-36720P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.20312023-10-10
CVE-2023-36720 [HIGH] CVE-2023-36720: Windows Mixed Reality Developer Tools Denial of Service Vulnerability
Windows Mixed Reality Developer Tools Denial of Service Vulnerability
nvd
CVE-2023-36431P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.20312023-10-10
CVE-2023-36431 [HIGH] CWE-400 CVE-2023-36431: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2023-36579P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.20312023-10-10
CVE-2023-36579 [HIGH] CWE-400 CVE-2023-36579: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2023-36581P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.20312023-10-10
CVE-2023-36581 [HIGH] CWE-126 CVE-2023-36581: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21276P3HIGHCVSS 7.5fixed in 10.0.20348.3091≥ 10.0.20348.0, < 10.0.20348.30912025-01-14
CVE-2025-21276 [HIGH] CWE-191 CVE-2025-21276: Windows MapUrlToZone Denial of Service Vulnerability
Windows MapUrlToZone Denial of Service Vulnerability
nvd
CVE-2024-43512P3HIGHCVSS 7.5fixed in 10.0.20348.2762≥ 10.0.20348.0, < 10.0.20348.27622024-10-08
CVE-2024-43512 [HIGH] CWE-835 CVE-2024-43512: Windows Standards-Based Storage Management Service Denial of Service Vulnerability
Windows Standards-Based Storage Management Service Denial of Service Vulnerability
nvd