Microsoft Windows Server 2022 vulnerabilities
3,303 known vulnerabilities affecting microsoft/windows_server_2022.
Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
135
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14
Vulnerabilities
Page 15 of 166
CVE-2026-50694P2CRITICALCVSS 9.8fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-50694 [CRITICAL] CWE-416 CVE-2026-50694: Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-30010P2HIGHCVSS 8.8fixed in 10.0.20348.2461≥ 10.0.20348.0, < 10.0.20348.24612024-05-14
CVE-2024-30010 [HIGH] CWE-23 CVE-2024-30010: Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2025-27480P3HIGHCVSS 8.1fixed in 10.0.20348.3453≥ 10.0.20348.0, < 10.0.20348.34532025-04-08
CVE-2025-27480 [HIGH] CWE-416 CVE-2025-27480: Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code ove
Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-43593P2HIGHCVSS 8.8fixed in 10.0.20348.2762≥ 10.0.20348.0, < 10.0.20348.27622024-10-08
CVE-2024-43593 [HIGH] CWE-20 CVE-2024-43593: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-43592P2HIGHCVSS 8.8fixed in 10.0.20348.2762≥ 10.0.20348.0, < 10.0.20348.27622024-10-08
CVE-2024-43592 [HIGH] CWE-20 CVE-2024-43592: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-38260P2HIGHCVSS 8.8fixed in 10.0.20348.2700≥ 10.0.20348.0, < 10.0.20348.27002024-09-10
CVE-2024-38260 [HIGH] CWE-908 CVE-2024-38260: Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
nvd
CVE-2025-64678P2HIGHCVSS 8.8fixed in 10.0.20348.4346≥ 10.0.20348.0, < 10.0.20348.44052025-12-09
CVE-2025-64678 [HIGH] CWE-122 CVE-2025-64678: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-49178P3HIGHCVSS 8.8fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-49178 [HIGH] CWE-122 CVE-2026-49178: Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to exec
Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
nvd
CVE-2022-21993P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.5242022-02-09
CVE-2022-21993 [HIGH] CVE-2022-21993: Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
nvd
CVE-2023-21708P2CRITICALCVSS 9.8≥ 10.0.20348.0, < 10.0.20348.16072023-03-14
CVE-2023-21708 [CRITICAL] CWE-191 CVE-2023-21708: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2024-43452P3HIGHCVSS 7.5fixed in 10.0.20348.2849≥ 10.0.20348.0, < 10.0.20348.28492024-11-12
CVE-2024-43452 [HIGH] CWE-367 CVE-2024-43452: Windows Registry Elevation of Privilege Vulnerability
Windows Registry Elevation of Privilege Vulnerability
nvd
CVE-2022-29129P3HIGHCVSS 8.8≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-29129 [HIGH] CVE-2022-29129: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29128P3HIGHCVSS 8.8≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-29128 [HIGH] CVE-2022-29128: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29131P3HIGHCVSS 8.8≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-29131 [HIGH] CVE-2022-29131: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29141P3HIGHCVSS 8.8≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-29141 [HIGH] CVE-2022-29141: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2026-42904P2CRITICALCVSS 9.6fixed in 10.0.20348.5256≥ 10.0.20348.0, < 10.0.20348.52562026-06-09
CVE-2026-42904 [CRITICAL] CWE-122 CVE-2026-42904: Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges o
Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.
nvd
CVE-2025-26647P2HIGHCVSS 8.8fixed in 10.0.20348.3453≥ 10.0.20348.0, < 10.0.20348.34532025-04-08
CVE-2025-26647 [HIGH] CWE-20 CVE-2025-26647: Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges ov
Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2025-50171P2CRITICALCVSS 9.1fixed in 10.0.20348.3989≥ 10.0.20348.0, < 10.0.20348.40522025-08-12
CVE-2025-50171 [CRITICAL] CWE-862 CVE-2025-50171: Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing o
Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-42985P3HIGHCVSS 8.8fixed in 10.0.20348.5256≥ 10.0.20348.0, < 10.0.20348.52562026-06-09
CVE-2026-42985 [HIGH] CWE-416 CVE-2026-42985: Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-50505P3HIGHCVSS 8.8fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-50505 [HIGH] CWE-416 CVE-2026-50505: Use after free in Windows Message Queuing allows an authorized attacker to execute code over a netwo
Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.
nvd