Microsoft Windows Server 2022 vulnerabilities
3,303 known vulnerabilities affecting microsoft/windows_server_2022.
Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
136
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14
Vulnerabilities
Page 124 of 166
CVE-2022-26827P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.6432022-04-15
CVE-2022-26827 [HIGH] CWE-362 CVE-2022-26827: Windows File Server Resource Management Service Elevation of Privilege Vulnerability
Windows File Server Resource Management Service Elevation of Privilege Vulnerability
nvd
CVE-2024-30012P4MEDIUMCVSS 6.8fixed in 10.0.20348.2461≥ 10.0.20348.0, < 10.0.20348.24612024-05-14
CVE-2024-30012 [MEDIUM] CWE-190 CVE-2024-30012: Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
nvd
CVE-2023-36405P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.21132023-11-14
CVE-2023-36405 [HIGH] CWE-362 CVE-2023-36405: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-26242P4HIGHCVSS 7.0fixed in 10.0.20348.2402≥ 10.0.20348.0, < 10.0.20348.24022024-04-09
CVE-2024-26242 [HIGH] CWE-591 CVE-2024-26242: Windows Telephony Server Elevation of Privilege Vulnerability
Windows Telephony Server Elevation of Privilege Vulnerability
nvd
CVE-2024-30021P4MEDIUMCVSS 6.8fixed in 10.0.20348.2461≥ 10.0.20348.0, < 10.0.20348.24612024-05-14
CVE-2024-30021 [MEDIUM] CWE-190 CVE-2024-30021: Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
nvd
CVE-2023-35361P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.18502023-07-11
CVE-2023-35361 [HIGH] CWE-362 CVE-2023-35361: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-35360P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.18502023-07-11
CVE-2023-35360 [HIGH] CWE-591 CVE-2023-35360: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-30063P4MEDIUMCVSS 6.7fixed in 10.0.20348.2522≥ 10.0.20348.0, < 10.0.20348.25272024-06-11
CVE-2024-30063 [MEDIUM] CWE-641 CVE-2024-30063: Windows Distributed File System (DFS) Remote Code Execution Vulnerability
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
nvd
CVE-2025-49678P4HIGHCVSS 7.0fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-49678 [HIGH] CWE-362 CVE-2025-49678: Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally
Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-24883P4MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.16682023-04-11
CVE-2023-24883 [MEDIUM] CWE-126 CVE-2023-24883: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-24906P4MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.16072023-03-14
CVE-2023-24906 [MEDIUM] CWE-190 CVE-2023-24906: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-24857P4MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.16072023-03-14
CVE-2023-24857 [MEDIUM] CWE-126 CVE-2023-24857: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-24863P4MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.16072023-03-14
CVE-2023-24863 [MEDIUM] CWE-190 CVE-2023-24863: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-24870P4MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.16072023-03-14
CVE-2023-24870 [MEDIUM] CWE-126 CVE-2023-24870: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2024-21431P4MEDIUMCVSS 6.7fixed in 10.0.20348.2340≥ 10.0.20348.0, < 10.0.20348.23402024-03-12
CVE-2024-21431 [MEDIUM] CWE-732 CVE-2024-21431: Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
nvd
CVE-2026-45658P4MEDIUMCVSS 6.8fixed in 10.0.20348.5256≥ 10.0.20348.0, < 10.0.20348.52562026-06-09
CVE-2026-45658 [MEDIUM] CWE-284 CVE-2026-45658: Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feat
Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-50298P4MEDIUMCVSS 6.8fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-50298 [MEDIUM] CWE-190 CVE-2026-50298: Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate p
Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2026-50299P4MEDIUMCVSS 6.8fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-50299 [MEDIUM] CWE-122 CVE-2026-50299: Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to e
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.
nvd
CVE-2026-57097P4MEDIUMCVSS 6.8fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-57097 [MEDIUM] CWE-426 CVE-2026-57097: Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature
Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48807P4MEDIUMCVSS 6.7fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.41712025-08-12
CVE-2025-48807 [MEDIUM] CWE-923 CVE-2025-48807: Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an aut
Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally.
nvd