cbcvebase.

Microsoft Windows Server 2022 vulnerabilities

3,303 known vulnerabilities affecting microsoft/windows_server_2022.

Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
136
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14

Vulnerabilities

Page 119 of 166
CVE-2023-21527P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.14872023-01-10
CVE-2023-21527 [HIGH] CWE-191 CVE-2023-21527: Windows iSCSI Service Denial of Service Vulnerability Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2023-35330P4HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.18502023-07-11
CVE-2023-35330 [HIGH] CWE-126 CVE-2023-35330: Windows Extended Negotiation Denial of Service Vulnerability Windows Extended Negotiation Denial of Service Vulnerability
nvd
CVE-2023-21811P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.15472023-02-14
CVE-2023-21811 [HIGH] CWE-126 CVE-2023-21811: Windows iSCSI Service Denial of Service Vulnerability Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2023-21700P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.15472023-02-14
CVE-2023-21700 [HIGH] CWE-476 CVE-2023-21700: Windows iSCSI Discovery Service Denial of Service Vulnerability Windows iSCSI Discovery Service Denial of Service Vulnerability
nvd
CVE-2023-21702P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.15472023-02-14
CVE-2023-21702 [HIGH] CWE-125 CVE-2023-21702: Windows iSCSI Service Denial of Service Vulnerability Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2022-24490P3MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.6432022-04-15
CVE-2022-24490 [MEDIUM] CVE-2022-24490: Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability
nvd
CVE-2022-38042P3HIGHCVSS 7.1≥ 10.0.20348.0, < 10.0.20348.11292022-10-11
CVE-2022-38042 [HIGH] CVE-2022-38042: Active Directory Domain Services Elevation of Privilege Vulnerability Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2022-26936P3MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-26936 [MEDIUM] CVE-2022-26936: Windows Server Service Information Disclosure Vulnerability Windows Server Service Information Disclosure Vulnerability
nvd
CVE-2023-36427P3HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.21132023-11-14
CVE-2023-36427 [HIGH] CVE-2023-36427: Windows Hyper-V Elevation of Privilege Vulnerability Windows Hyper-V Elevation of Privilege Vulnerability
nvd
CVE-2022-22015P3MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-22015 [MEDIUM] CVE-2022-22015: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
nvd
CVE-2022-26940P3MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-26940 [MEDIUM] CVE-2022-26940: Remote Desktop Protocol Client Information Disclosure Vulnerability Remote Desktop Protocol Client Information Disclosure Vulnerability
nvd
CVE-2024-20659P4HIGHCVSS 7.1fixed in 10.0.20348.2762≥ 10.0.20348.0, < 10.0.20348.27622024-10-08
CVE-2024-20659 [HIGH] CWE-20 CVE-2024-20659: Windows Hyper-V Security Feature Bypass Vulnerability Windows Hyper-V Security Feature Bypass Vulnerability
nvd
CVE-2024-49082P4MEDIUMCVSS 6.8fixed in 10.0.20348.2966≥ 10.0.20348.0, < 10.0.20348.29662024-12-12
CVE-2024-49082 [MEDIUM] CWE-22 CVE-2024-49082: Windows File Explorer Information Disclosure Vulnerability Windows File Explorer Information Disclosure Vulnerability
nvd
CVE-2024-21314P3MEDIUMCVSS 6.5fixed in 10.0.20348.2227≥ 10.0.20348.0, < 10.0.20348.22272024-01-09
CVE-2024-21314 [MEDIUM] CWE-125 CVE-2024-21314: Microsoft Message Queuing Information Disclosure Vulnerability Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2025-25008P4HIGHCVSS 7.1fixed in 10.0.20348.3328≥ 10.0.20348.0, < 10.0.20348.33282025-03-11
CVE-2025-25008 [HIGH] CWE-59 CVE-2025-25008: Improper link resolution before file access ('link following') in Microsoft Windows allows an author Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-20660P4MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.22272024-01-09
CVE-2024-20660 [MEDIUM] CWE-125 CVE-2024-20660: Microsoft Message Queuing Information Disclosure Vulnerability Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2024-20680P4MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.22272024-01-09
CVE-2024-20680 [MEDIUM] CWE-822 CVE-2024-20680: Windows Message Queuing Client (MSMQC) Information Disclosure Windows Message Queuing Client (MSMQC) Information Disclosure
nvd
CVE-2022-21864P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.4692022-01-11
CVE-2022-21864 [HIGH] CVE-2022-21864: Windows UI Immersive Server API Elevation of Privilege Vulnerability Windows UI Immersive Server API Elevation of Privilege Vulnerability
nvd
CVE-2022-21860P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.4692022-01-11
CVE-2022-21860 [HIGH] CVE-2022-21860: Windows AppContracts API Server Elevation of Privilege Vulnerability Windows AppContracts API Server Elevation of Privilege Vulnerability
nvd
CVE-2024-20664P3MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.22272024-01-09
CVE-2024-20664 [MEDIUM] CWE-822 CVE-2024-20664: Microsoft Message Queuing Information Disclosure Vulnerability Microsoft Message Queuing Information Disclosure Vulnerability
nvd
Microsoft Windows Server 2022 vulnerabilities | cvebase