cbcvebase.

Microsoft Windows Server 2022 vulnerabilities

3,303 known vulnerabilities affecting microsoft/windows_server_2022.

Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
136
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14

Vulnerabilities

Page 129 of 166
CVE-2022-29138P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-29138 [HIGH] CVE-2022-29138: Windows Clustered Shared Volume Elevation of Privilege Vulnerability Windows Clustered Shared Volume Elevation of Privilege Vulnerability
nvd
CVE-2022-29106P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-29106 [HIGH] CVE-2022-29106: Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability
nvd
CVE-2024-43534P4MEDIUMCVSS 6.5fixed in 10.0.20348.2762≥ 10.0.20348.0, < 10.0.20348.27622024-10-08
CVE-2024-43534 [MEDIUM] CWE-125 CVE-2024-43534: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2022-38027P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.11292022-10-11
CVE-2022-38027 [HIGH] CWE-362 CVE-2022-38027: Windows Storage Elevation of Privilege Vulnerability Windows Storage Elevation of Privilege Vulnerability
nvd
CVE-2023-29368P4HIGHCVSS 7.0fixed in 10.0.20348.1787≥ 10.0.20348.0, < 10.0.20348.17872023-06-14
CVE-2023-29368 [HIGH] CWE-415 CVE-2023-29368: Windows Filtering Platform Elevation of Privilege Vulnerability Windows Filtering Platform Elevation of Privilege Vulnerability
nvd
CVE-2023-28216P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.16682023-04-11
CVE-2023-28216 [HIGH] CVE-2023-28216: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
nvd
CVE-2022-26828P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.6432022-04-15
CVE-2022-26828 [HIGH] CWE-362 CVE-2022-26828: Windows Bluetooth Driver Elevation of Privilege Vulnerability Windows Bluetooth Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-6769P4MEDIUMCVSS 6.7v10.0.02024-09-26
CVE-2024-6769 [MEDIUM] CWE-426 CVE-2024-6769: A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Micro A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated attacker to elevate from a medium integrity process to a high integrity process without the intervention of a UAC prompt.
nvd
CVE-2023-23385P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.16072023-03-14
CVE-2023-23385 [HIGH] CWE-190 CVE-2023-23385: Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability
nvd
CVE-2022-26807P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.6432022-04-15
CVE-2022-26807 [HIGH] CWE-362 CVE-2022-26807: Windows Work Folder Service Elevation of Privilege Vulnerability Windows Work Folder Service Elevation of Privilege Vulnerability
nvd
CVE-2022-44669P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.13662022-12-13
CVE-2022-44669 [HIGH] CWE-362 CVE-2022-44669: Windows Error Reporting Elevation of Privilege Vulnerability Windows Error Reporting Elevation of Privilege Vulnerability
nvd
CVE-2023-21733P4HIGHCVSS 7.0≥ 10.0.20348.0, < 10.0.20348.14872023-01-10
CVE-2023-21733 [HIGH] CWE-122 CVE-2023-21733: Windows Bind Filter Driver Elevation of Privilege Vulnerability Windows Bind Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-30205P4MEDIUMCVSS 6.6≥ 10.0.20348.0, < 10.0.20348.8252022-07-12
CVE-2022-30205 [MEDIUM] CWE-362 CVE-2022-30205: Windows Group Policy Elevation of Privilege Vulnerability Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2025-48800P4MEDIUMCVSS 6.8fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-48800 [MEDIUM] CWE-693 CVE-2025-48800: Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a securi Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48003P4MEDIUMCVSS 6.8fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-48003 [MEDIUM] CWE-693 CVE-2025-48003: Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a securi Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48804P4MEDIUMCVSS 6.8fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-48804 [MEDIUM] CWE-349 CVE-2025-48804: Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorize Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48818P4MEDIUMCVSS 6.8fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-48818 [MEDIUM] CWE-367 CVE-2025-48818: Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attack Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48001P4MEDIUMCVSS 6.8fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-48001 [MEDIUM] CWE-367 CVE-2025-48001: Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attack Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2024-21430P4MEDIUMCVSS 6.4fixed in 10.0.20348.2340≥ 10.0.20348.0, < 10.0.20348.23402024-03-12
CVE-2024-21430 [MEDIUM] CWE-125 CVE-2024-21430: Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability
nvd
CVE-2024-21339P4MEDIUMCVSS 6.4fixed in 10.0.20348.2322≥ 10.0.20348.0, < 10.0.20348.23222024-02-13
CVE-2024-21339 [MEDIUM] CWE-416 CVE-2024-21339: Windows USB Generic Parent Driver Remote Code Execution Vulnerability Windows USB Generic Parent Driver Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2022 vulnerabilities | cvebase