cbcvebase.

Microsoft Windows Server 2022 vulnerabilities

3,303 known vulnerabilities affecting microsoft/windows_server_2022.

Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
136
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14

Vulnerabilities

Page 120 of 166
CVE-2024-20663P4MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.22272024-01-09
CVE-2024-20663 [MEDIUM] CWE-822 CVE-2024-20663: Windows Message Queuing Client (MSMQC) Information Disclosure Windows Message Queuing Client (MSMQC) Information Disclosure
nvd
CVE-2023-36706P3MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.20312023-10-10
CVE-2023-36706 [MEDIUM] CWE-20 CVE-2023-36706: Windows Deployment Services Information Disclosure Vulnerability Windows Deployment Services Information Disclosure Vulnerability
nvd
CVE-2022-23298P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.5872022-03-09
CVE-2022-23298 [HIGH] CVE-2022-23298: Windows NT OS Kernel Elevation of Privilege Vulnerability Windows NT OS Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-38022P4HIGHCVSS 7.0fixed in 10.0.20348.2582≥ 10.0.20348.0, < 10.0.20348.25822024-07-09
CVE-2024-38022 [HIGH] CWE-59 CVE-2024-38022: Windows Image Acquisition Elevation of Privilege Vulnerability Windows Image Acquisition Elevation of Privilege Vulnerability
nvd
CVE-2023-36403P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.21132023-11-14
CVE-2023-36403 [HIGH] CWE-591 CVE-2023-36403: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-43535P4HIGHCVSS 7.0fixed in 10.0.20348.2762≥ 10.0.20348.0, < 10.0.20348.27622024-10-08
CVE-2024-43535 [HIGH] CWE-416 CVE-2024-43535: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-43570P4HIGHCVSS 7.0fixed in 10.0.20348.2762≥ 10.0.20348.0, < 10.0.20348.27622024-10-08
CVE-2024-43570 [HIGH] CWE-416 CVE-2024-43570: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2026-49165P4HIGHCVSS 7.1fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-49165 [HIGH] CWE-908 CVE-2026-49165: Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclo Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.
nvd
CVE-2024-49084P4HIGHCVSS 7.0fixed in 10.0.20348.2966≥ 10.0.20348.0, < 10.0.20348.29662024-12-12
CVE-2024-49084 [HIGH] CWE-362 CVE-2024-49084: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-38136P4HIGHCVSS 7.0fixed in 10.0.20348.2655≥ 10.0.20348.0, < 10.0.20348.26552024-08-13
CVE-2024-38136 [HIGH] CWE-416 CVE-2024-38136: Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability
nvd
CVE-2024-38137P4HIGHCVSS 7.0fixed in 10.0.20348.2655≥ 10.0.20348.0, < 10.0.20348.26552024-08-13
CVE-2024-38137 [HIGH] CWE-416 CVE-2024-38137: Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability
nvd
CVE-2024-43511P4HIGHCVSS 7.0fixed in 10.0.20348.2762≥ 10.0.20348.0, < 10.0.20348.28492024-10-08
CVE-2024-43511 [HIGH] CWE-367 CVE-2024-43511: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-29364P4HIGHCVSS 7.0fixed in 10.0.20348.1787≥ 10.0.20348.0, < 10.0.20348.17872023-06-14
CVE-2023-29364 [HIGH] CWE-190 CVE-2023-29364: Windows Authentication Elevation of Privilege Vulnerability Windows Authentication Elevation of Privilege Vulnerability
nvd
CVE-2024-38069P4HIGHCVSS 7.0fixed in 10.0.20348.2582≥ 10.0.20348.0, < 10.0.20348.25822024-07-09
CVE-2024-38069 [HIGH] CWE-347 CVE-2024-38069: Windows Enroll Engine Security Feature Bypass Vulnerability Windows Enroll Engine Security Feature Bypass Vulnerability
nvd
CVE-2025-49685P4HIGHCVSS 7.0fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-49685 [HIGH] CWE-416 CVE-2025-49685: Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privil Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-21191P4HIGHCVSS 7.0fixed in 10.0.20348.3453≥ 10.0.20348.0, < 10.0.20348.34532025-04-08
CVE-2025-21191 [HIGH] CWE-367 CVE-2025-21191: Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows a Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-38033P3MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.11292022-10-11
CVE-2022-38033 [MEDIUM] CVE-2022-38033: Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability
nvd
CVE-2025-21301P4MEDIUMCVSS 6.5fixed in 10.0.20348.3091≥ 10.0.20348.0, < 10.0.20348.30912025-01-14
CVE-2025-21301 [MEDIUM] CWE-284 CVE-2025-21301: Windows Geolocation Service Information Disclosure Vulnerability Windows Geolocation Service Information Disclosure Vulnerability
nvd
CVE-2023-24865P3MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.16072023-03-14
CVE-2023-24865 [MEDIUM] CWE-20 CVE-2023-24865: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-24866P3MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.16072023-03-14
CVE-2023-24866 [MEDIUM] CWE-20 CVE-2023-24866: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
Microsoft Windows Server 2022 vulnerabilities | cvebase