Microsoft Windows Server 2022 vulnerabilities
3,303 known vulnerabilities affecting microsoft/windows_server_2022.
Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
136
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14
Vulnerabilities
Page 143 of 166
CVE-2022-29122P4MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-29122 [MEDIUM] CVE-2022-29122: Windows Clustered Shared Volume Information Disclosure Vulnerability
Windows Clustered Shared Volume Information Disclosure Vulnerability
nvd
CVE-2022-29123P4MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-29123 [MEDIUM] CVE-2022-29123: Windows Clustered Shared Volume Information Disclosure Vulnerability
Windows Clustered Shared Volume Information Disclosure Vulnerability
nvd
CVE-2022-21906P4MEDIUMCVSS 5.5≥ 10.0.20348.0, < 10.0.20348.4692022-01-11
CVE-2022-21906 [MEDIUM] CVE-2022-21906: Windows Defender Application Control Security Feature Bypass Vulnerability
Windows Defender Application Control Security Feature Bypass Vulnerability
nvd
CVE-2023-36801P4MEDIUMCVSS 5.3≥ 10.0.20348.0, < 10.0.20348.19702023-09-12
CVE-2023-36801 [MEDIUM] CWE-126 CVE-2023-36801: DHCP Server Service Information Disclosure Vulnerability
DHCP Server Service Information Disclosure Vulnerability
nvd
CVE-2025-24992P4MEDIUMCVSS 5.5fixed in 10.0.20348.3270≥ 10.0.20348.0, < 10.0.20348.33282025-03-11
CVE-2025-24992 [MEDIUM] CWE-126 CVE-2025-24992: Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.
nvd
CVE-2023-21682P4MEDIUMCVSS 5.3≥ 10.0.20348.0, < 10.0.20348.14872023-01-10
CVE-2023-21682 [MEDIUM] CWE-125 CVE-2023-21682: Windows Point-to-Point Protocol (PPP) Information Disclosure Vulnerability
Windows Point-to-Point Protocol (PPP) Information Disclosure Vulnerability
nvd
CVE-2023-29355P4MEDIUMCVSS 5.3≥ 10.0.20348.0, < 10.0.20348.17872023-06-14
CVE-2023-29355 [MEDIUM] CWE-668 CVE-2023-29355: DHCP Server Service Information Disclosure Vulnerability
DHCP Server Service Information Disclosure Vulnerability
nvd
CVE-2024-43554P4MEDIUMCVSS 5.5fixed in 10.0.20348.2762≥ 10.0.20348.0, < 10.0.20348.27622024-10-08
CVE-2024-43554 [MEDIUM] CWE-212 CVE-2024-43554: Windows Kernel-Mode Driver Information Disclosure Vulnerability
Windows Kernel-Mode Driver Information Disclosure Vulnerability
nvd
CVE-2025-33055P4MEDIUMCVSS 5.5fixed in 10.0.20348.3745≥ 10.0.20348.0, < 10.0.20348.38072025-06-10
CVE-2025-33055 [MEDIUM] CWE-125 CVE-2025-33055: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-33062P4MEDIUMCVSS 5.5fixed in 10.0.20348.3745≥ 10.0.20348.0, < 10.0.20348.38072025-06-10
CVE-2025-33062 [MEDIUM] CWE-125 CVE-2025-33062: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-33063P4MEDIUMCVSS 5.5fixed in 10.0.20348.3745≥ 10.0.20348.0, < 10.0.20348.38072025-06-10
CVE-2025-33063 [MEDIUM] CWE-125 CVE-2025-33063: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-33061P4MEDIUMCVSS 5.5fixed in 10.0.20348.3745≥ 10.0.20348.0, < 10.0.20348.38072025-06-10
CVE-2025-33061 [MEDIUM] CWE-125 CVE-2025-33061: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-24069P4MEDIUMCVSS 5.5fixed in 10.0.20348.3745≥ 10.0.20348.0, < 10.0.20348.38072025-06-10
CVE-2025-24069 [MEDIUM] CWE-125 CVE-2025-24069: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-33058P4MEDIUMCVSS 5.5fixed in 10.0.20348.3745≥ 10.0.20348.0, < 10.0.20348.38072025-06-10
CVE-2025-33058 [MEDIUM] CWE-125 CVE-2025-33058: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-33060P4MEDIUMCVSS 5.5fixed in 10.0.20348.3745≥ 10.0.20348.0, < 10.0.20348.38072025-06-10
CVE-2025-33060 [MEDIUM] CWE-125 CVE-2025-33060: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-33059P4MEDIUMCVSS 5.5fixed in 10.0.20348.3745≥ 10.0.20348.0, < 10.0.20348.38072025-06-10
CVE-2025-33059 [MEDIUM] CWE-125 CVE-2025-33059: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-33065P4MEDIUMCVSS 5.5fixed in 10.0.20348.3745≥ 10.0.20348.0, < 10.0.20348.38072025-06-10
CVE-2025-33065 [MEDIUM] CWE-125 CVE-2025-33065: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-24065P4MEDIUMCVSS 5.5fixed in 10.0.20348.3745≥ 10.0.20348.0, < 10.0.20348.38072025-06-10
CVE-2025-24065 [MEDIUM] CWE-125 CVE-2025-24065: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-32719P4MEDIUMCVSS 5.5fixed in 10.0.20348.3745≥ 10.0.20348.0, < 10.0.20348.38072025-06-10
CVE-2025-32719 [MEDIUM] CWE-125 CVE-2025-32719: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-29829P4MEDIUMCVSS 5.5fixed in 10.0.20348.3692≥ 10.0.20348.0, < 10.0.20348.36922025-05-13
CVE-2025-29829 [MEDIUM] CWE-908 CVE-2025-29829: Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attac
Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.
nvd