Microsoft Windows Server 2022 vulnerabilities
3,303 known vulnerabilities affecting microsoft/windows_server_2022.
Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
136
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14
Vulnerabilities
Page 129 of 166
CVE-2022-29138P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-29138 [HIGH] CVE-2022-29138: Windows Clustered Shared Volume Elevation of Privilege Vulnerability
Windows Clustered Shared Volume Elevation of Privilege Vulnerability
nvd
CVE-2022-29106P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-29106 [HIGH] CVE-2022-29106: Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability
Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability
nvd
CVE-2024-43534P4MEDIUMCVSS 6.5fixed in 10.0.20348.2762≥ 10.0.20348.0, < 10.0.20348.27622024-10-08
CVE-2024-43534 [MEDIUM] CWE-125 CVE-2024-43534: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2022-38027P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.11292022-10-11
CVE-2022-38027 [HIGH] CWE-362 CVE-2022-38027: Windows Storage Elevation of Privilege Vulnerability
Windows Storage Elevation of Privilege Vulnerability
nvd
CVE-2023-29368P4HIGHCVSS 7.0fixed in 10.0.20348.1787≥ 10.0.20348.0, < 10.0.20348.17872023-06-14
CVE-2023-29368 [HIGH] CWE-415 CVE-2023-29368: Windows Filtering Platform Elevation of Privilege Vulnerability
Windows Filtering Platform Elevation of Privilege Vulnerability
nvd
CVE-2023-28216P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.16682023-04-11
CVE-2023-28216 [HIGH] CVE-2023-28216: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
nvd
CVE-2022-26828P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.6432022-04-15
CVE-2022-26828 [HIGH] CWE-362 CVE-2022-26828: Windows Bluetooth Driver Elevation of Privilege Vulnerability
Windows Bluetooth Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-6769P4MEDIUMCVSS 6.7v10.0.02024-09-26
CVE-2024-6769 [MEDIUM] CWE-426 CVE-2024-6769: A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Micro
A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated attacker to elevate from a medium integrity process to a high integrity process without the intervention of a UAC prompt.
nvd
CVE-2023-23385P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.16072023-03-14
CVE-2023-23385 [HIGH] CWE-190 CVE-2023-23385: Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability
Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability
nvd
CVE-2022-26807P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.6432022-04-15
CVE-2022-26807 [HIGH] CWE-362 CVE-2022-26807: Windows Work Folder Service Elevation of Privilege Vulnerability
Windows Work Folder Service Elevation of Privilege Vulnerability
nvd
CVE-2022-44669P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.13662022-12-13
CVE-2022-44669 [HIGH] CWE-362 CVE-2022-44669: Windows Error Reporting Elevation of Privilege Vulnerability
Windows Error Reporting Elevation of Privilege Vulnerability
nvd
CVE-2023-21733P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.14872023-01-10
CVE-2023-21733 [HIGH] CWE-122 CVE-2023-21733: Windows Bind Filter Driver Elevation of Privilege Vulnerability
Windows Bind Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-30205P4MEDIUMCVSS 6.6≥ 10.0.20348.0, < 10.0.20348.8252022-07-12
CVE-2022-30205 [MEDIUM] CWE-362 CVE-2022-30205: Windows Group Policy Elevation of Privilege Vulnerability
Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2025-48800P4MEDIUMCVSS 6.8fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-48800 [MEDIUM] CWE-693 CVE-2025-48800: Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a securi
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48003P4MEDIUMCVSS 6.8fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-48003 [MEDIUM] CWE-693 CVE-2025-48003: Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a securi
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48804P4MEDIUMCVSS 6.8fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-48804 [MEDIUM] CWE-349 CVE-2025-48804: Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorize
Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48818P4MEDIUMCVSS 6.8fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-48818 [MEDIUM] CWE-367 CVE-2025-48818: Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attack
Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48001P4MEDIUMCVSS 6.8fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-48001 [MEDIUM] CWE-367 CVE-2025-48001: Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attack
Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2024-21430P4MEDIUMCVSS 6.4fixed in 10.0.20348.2340≥ 10.0.20348.0, < 10.0.20348.23402024-03-12
CVE-2024-21430 [MEDIUM] CWE-125 CVE-2024-21430: Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability
Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability
nvd
CVE-2024-21339P4MEDIUMCVSS 6.4fixed in 10.0.20348.2322≥ 10.0.20348.0, < 10.0.20348.23222024-02-13
CVE-2024-21339 [MEDIUM] CWE-416 CVE-2024-21339: Windows USB Generic Parent Driver Remote Code Execution Vulnerability
Windows USB Generic Parent Driver Remote Code Execution Vulnerability
nvd