cbcvebase.

Microsoft Windows Server 2022 vulnerabilities

3,303 known vulnerabilities affecting microsoft/windows_server_2022.

Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
136
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14

Vulnerabilities

Page 112 of 166
CVE-2026-42903P3MEDIUMCVSS 6.5fixed in 10.0.20348.5256≥ 10.0.20348.0, < 10.0.20348.52562026-06-09
CVE-2026-42903 [MEDIUM] CWE-476 CVE-2026-42903: Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a ne Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.
nvd
CVE-2022-21883P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.4692022-01-11
CVE-2022-21883 [HIGH] CVE-2022-21883: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2026-26155P3MEDIUMCVSS 6.5fixed in 10.0.20348.5020≥ 10.0.20348.0, < 10.0.20348.50202026-04-14
CVE-2026-26155 [MEDIUM] CWE-126 CVE-2026-26155: Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
nvd
CVE-2026-49799P3MEDIUMCVSS 6.5fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-49799 [MEDIUM] CWE-400 CVE-2026-49799: Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allo Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.
nvd
CVE-2022-21848P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.4692022-01-11
CVE-2022-21848 [HIGH] CVE-2022-21848: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2021-43219P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.20348.4052021-12-15
CVE-2021-43219 [HIGH] CVE-2021-43219: DirectX Graphics Kernel File Denial of Service Vulnerability DirectX Graphics Kernel File Denial of Service Vulnerability
nvd
CVE-2022-34724P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.10062022-09-13
CVE-2022-34724 [HIGH] CVE-2022-34724: Windows DNS Server Denial of Service Vulnerability Windows DNS Server Denial of Service Vulnerability
nvd
CVE-2022-34720P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.10062022-09-13
CVE-2022-34720 [HIGH] CVE-2022-34720: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2022-26915P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.6432022-04-15
CVE-2022-26915 [HIGH] CVE-2022-26915: Windows Secure Channel Denial of Service Vulnerability Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2022-30202P3HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.8252022-07-12
CVE-2022-30202 [HIGH] CVE-2022-30202: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
nvd
CVE-2024-20661P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.22272024-01-09
CVE-2024-20661 [HIGH] CWE-476 CVE-2024-20661: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2022-30152P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.7702022-06-15
CVE-2022-30152 [HIGH] CVE-2022-30152: Windows Network Address Translation (NAT) Denial of Service Vulnerability Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2023-36707P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.20312023-10-10
CVE-2023-36707 [HIGH] CWE-20 CVE-2023-36707: Windows Deployment Services Denial of Service Vulnerability Windows Deployment Services Denial of Service Vulnerability
nvd
CVE-2024-30083P3HIGHCVSS 7.5fixed in 10.0.20348.2522≥ 10.0.20348.0, < 10.0.20348.25272024-06-11
CVE-2024-30083 [HIGH] CWE-121 CVE-2024-30083: Windows Standards-Based Storage Management Service Denial of Service Vulnerability Windows Standards-Based Storage Management Service Denial of Service Vulnerability
nvd
CVE-2023-36720P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.20312023-10-10
CVE-2023-36720 [HIGH] CVE-2023-36720: Windows Mixed Reality Developer Tools Denial of Service Vulnerability Windows Mixed Reality Developer Tools Denial of Service Vulnerability
nvd
CVE-2023-36431P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.20312023-10-10
CVE-2023-36431 [HIGH] CWE-400 CVE-2023-36431: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2023-36579P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.20312023-10-10
CVE-2023-36579 [HIGH] CWE-400 CVE-2023-36579: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2023-36581P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.20312023-10-10
CVE-2023-36581 [HIGH] CWE-126 CVE-2023-36581: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21276P3HIGHCVSS 7.5fixed in 10.0.20348.3091≥ 10.0.20348.0, < 10.0.20348.30912025-01-14
CVE-2025-21276 [HIGH] CWE-191 CVE-2025-21276: Windows MapUrlToZone Denial of Service Vulnerability Windows MapUrlToZone Denial of Service Vulnerability
nvd
CVE-2024-43512P3HIGHCVSS 7.5fixed in 10.0.20348.2762≥ 10.0.20348.0, < 10.0.20348.27622024-10-08
CVE-2024-43512 [HIGH] CWE-835 CVE-2024-43512: Windows Standards-Based Storage Management Service Denial of Service Vulnerability Windows Standards-Based Storage Management Service Denial of Service Vulnerability
nvd
Microsoft Windows Server 2022 vulnerabilities | cvebase