cbcvebase.

Microsoft Windows Server 2022 vulnerabilities

3,303 known vulnerabilities affecting microsoft/windows_server_2022.

Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
136
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14

Vulnerabilities

Page 128 of 166
CVE-2026-25185P4MEDIUMCVSS 5.3fixed in 10.0.20348.4830≥ 10.0.20348.0, < 10.0.20348.48932026-03-10
CVE-2026-25185 [MEDIUM] CWE-200 CVE-2026-25185: Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows a Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2025-62567P4MEDIUMCVSS 5.3fixed in 10.0.20348.4467≥ 10.0.20348.0, < 10.0.20348.45292025-12-09
CVE-2025-62567 [MEDIUM] CWE-191 CVE-2025-62567: Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny serv Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network.
nvd
CVE-2022-24460P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.5872022-03-09
CVE-2022-24460 [HIGH] CVE-2022-24460: Tablet Windows User Interface Application Elevation of Privilege Vulnerability Tablet Windows User Interface Application Elevation of Privilege Vulnerability
nvd
CVE-2022-29112P4MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-29112 [MEDIUM] CVE-2022-29112: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2024-26197P4MEDIUMCVSS 6.5fixed in 10.0.20348.2340≥ 10.0.20348.0, < 10.0.20348.23402024-03-12
CVE-2024-26197 [MEDIUM] CWE-20 CVE-2024-26197: Windows Standards-Based Storage Management Service Denial of Service Vulnerability Windows Standards-Based Storage Management Service Denial of Service Vulnerability
nvd
CVE-2023-21750P4HIGHCVSS 7.1≥ 10.0.20348.0, < 10.0.20348.14872023-01-10
CVE-2023-21750 [HIGH] CWE-284 CVE-2023-21750: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-28222P4HIGHCVSS 7.1≥ 10.0.20348.0, < 10.0.20348.16682023-04-11
CVE-2023-28222 [HIGH] CWE-59 CVE-2023-28222: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-28267P4MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.16682023-04-11
CVE-2023-28267 [MEDIUM] CWE-126 CVE-2023-28267: Remote Desktop Protocol Client Information Disclosure Vulnerability Remote Desktop Protocol Client Information Disclosure Vulnerability
nvd
CVE-2022-30225P4HIGHCVSS 7.1≥ 10.0.20348.0, < 10.0.20348.8252022-07-12
CVE-2022-30225 [HIGH] CVE-2022-30225: Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability
nvd
CVE-2022-29135P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-29135 [HIGH] CVE-2022-29135: Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability
nvd
CVE-2022-29125P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-29125 [HIGH] CVE-2022-29125: Windows Push Notifications Apps Elevation of Privilege Vulnerability Windows Push Notifications Apps Elevation of Privilege Vulnerability
nvd
CVE-2022-21867P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.4692022-01-11
CVE-2022-21867 [HIGH] CVE-2022-21867: Windows Push Notifications Apps Elevation of Privilege Vulnerability Windows Push Notifications Apps Elevation of Privilege Vulnerability
nvd
CVE-2023-28224P4HIGHCVSS 7.1≥ 10.0.20348.0, < 10.0.20348.16682023-04-11
CVE-2023-28224 [HIGH] CWE-591 CVE-2023-28224: Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
nvd
CVE-2023-23407P4HIGHCVSS 7.1≥ 10.0.20348.0, < 10.0.20348.16072023-03-14
CVE-2023-23407 [HIGH] CWE-591 CVE-2023-23407: Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
nvd
CVE-2023-23414P4HIGHCVSS 7.1≥ 10.0.20348.0, < 10.0.20348.16072023-03-14
CVE-2023-23414 [HIGH] CWE-591 CVE-2023-23414: Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
nvd
CVE-2022-29151P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-29151 [HIGH] CVE-2022-29151: Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability
nvd
CVE-2022-29150P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-29150 [HIGH] CVE-2022-29150: Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability
nvd
CVE-2022-21896P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.4692022-01-11
CVE-2022-21896 [HIGH] CWE-362 CVE-2022-21896: Windows DWM Core Library Elevation of Privilege Vulnerability Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2022-23288P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.5872022-03-09
CVE-2022-23288 [HIGH] CVE-2022-23288: Windows DWM Core Library Elevation of Privilege Vulnerability Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2023-35329P4MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.18502023-07-11
CVE-2023-35329 [MEDIUM] CWE-400 CVE-2023-35329: Windows Authentication Denial of Service Vulnerability Windows Authentication Denial of Service Vulnerability
nvd
Microsoft Windows Server 2022 vulnerabilities | cvebase