Microsoft Windows Server 2022 vulnerabilities
3,303 known vulnerabilities affecting microsoft/windows_server_2022.
Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
136
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14
Vulnerabilities
Page 150 of 166
CVE-2024-21311P4MEDIUMCVSS 5.5fixed in 10.0.20348.2227≥ 10.0.20348.0, < 10.0.20348.22272024-01-09
CVE-2024-21311 [MEDIUM] CWE-125 CVE-2024-21311: Windows Cryptographic Services Information Disclosure Vulnerability
Windows Cryptographic Services Information Disclosure Vulnerability
nvd
CVE-2023-36404P4MEDIUMCVSS 5.5≥ 10.0.20348.0, < 10.0.20348.21132023-11-14
CVE-2023-36404 [MEDIUM] CWE-284 CVE-2023-36404: Windows Kernel Information Disclosure Vulnerability
Windows Kernel Information Disclosure Vulnerability
nvd
CVE-2021-38662P4MEDIUMCVSS 5.5≥ 10.0.0, < 10.0.20348.2882021-10-13
CVE-2021-38662 [MEDIUM] CVE-2021-38662: Windows Fast FAT File System Driver Information Disclosure Vulnerability
Windows Fast FAT File System Driver Information Disclosure Vulnerability
nvd
CVE-2021-40468P4MEDIUMCVSS 5.5≥ 10.0.0, < 10.0.20348.2882021-10-13
CVE-2021-40468 [MEDIUM] CVE-2021-40468: Windows Bind Filter Driver Information Disclosure Vulnerability
Windows Bind Filter Driver Information Disclosure Vulnerability
nvd
CVE-2021-41343P4MEDIUMCVSS 5.5≥ 10.0.0, < 10.0.20348.2882021-10-13
CVE-2021-41343 [MEDIUM] CVE-2021-41343: Windows Fast FAT File System Driver Information Disclosure Vulnerability
Windows Fast FAT File System Driver Information Disclosure Vulnerability
nvd
CVE-2021-38663P4MEDIUMCVSS 5.5≥ 10.0.0, < 10.0.20348.2882021-10-13
CVE-2021-38663 [MEDIUM] CVE-2021-38663: Windows exFAT File System Information Disclosure Vulnerability
Windows exFAT File System Information Disclosure Vulnerability
nvd
CVE-2023-33174P4MEDIUMCVSS 5.5≥ 10.0.20348.0, < 10.0.20348.18502023-07-11
CVE-2023-33174 [MEDIUM] CWE-200 CVE-2023-33174: Windows Cryptographic Information Disclosure Vulnerability
Windows Cryptographic Information Disclosure Vulnerability
nvd
CVE-2023-32041P4MEDIUMCVSS 5.5≥ 10.0.20348.0, < 10.0.20348.18502023-07-11
CVE-2023-32041 [MEDIUM] CWE-908 CVE-2023-32041: Windows Update Orchestrator Service Information Disclosure Vulnerability
Windows Update Orchestrator Service Information Disclosure Vulnerability
nvd
CVE-2024-38151P4MEDIUMCVSS 5.5fixed in 10.0.20348.2655≥ 10.0.20348.0, < 10.0.20348.26552024-08-13
CVE-2024-38151 [MEDIUM] CWE-125 CVE-2024-38151: Windows Kernel Information Disclosure Vulnerability
Windows Kernel Information Disclosure Vulnerability
nvd
CVE-2025-21374P4MEDIUMCVSS 5.5fixed in 10.0.20348.3091≥ 10.0.20348.0, < 10.0.20348.30912025-01-14
CVE-2025-21374 [MEDIUM] CWE-125 CVE-2025-21374: Windows CSC Service Information Disclosure Vulnerability
Windows CSC Service Information Disclosure Vulnerability
nvd
CVE-2022-38025P4MEDIUMCVSS 5.5≥ 10.0.20348.0, < 10.0.20348.11292022-10-11
CVE-2022-38025 [MEDIUM] CVE-2022-38025: Windows Distributed File System (DFS) Information Disclosure Vulnerability
Windows Distributed File System (DFS) Information Disclosure Vulnerability
nvd
CVE-2023-24945P4MEDIUMCVSS 5.5≥ 10.0.20348.0, < 10.0.20348.17262023-05-09
CVE-2023-24945 [MEDIUM] CWE-190 CVE-2023-24945: Windows iSCSI Target Service Information Disclosure Vulnerability
Windows iSCSI Target Service Information Disclosure Vulnerability
nvd
CVE-2022-41055P4MEDIUMCVSS 5.5≥ 10.0.20348.0, < 10.0.20348.12492022-11-09
CVE-2022-41055 [MEDIUM] CVE-2022-41055: Windows Human Interface Device Information Disclosure Vulnerability
Windows Human Interface Device Information Disclosure Vulnerability
nvd
CVE-2023-35326P4MEDIUMCVSS 5.5≥ 10.0.20348.0, < 10.0.20348.18502023-07-11
CVE-2023-35326 [MEDIUM] CWE-908 CVE-2023-35326: Windows CDP User Components Information Disclosure Vulnerability
Windows CDP User Components Information Disclosure Vulnerability
nvd
CVE-2021-40454P4MEDIUMCVSS 5.5≥ 10.0.0, < 10.0.20348.2882021-10-13
CVE-2021-40454 [MEDIUM] CWE-312 CVE-2021-40454: Rich Text Edit Control Information Disclosure Vulnerability
Rich Text Edit Control Information Disclosure Vulnerability
nvd
CVE-2025-48813P4MEDIUMCVSS 4.7fixed in 10.0.20348.4294≥ 10.0.20348.0, < 10.0.20348.42942025-10-14
CVE-2025-48813 [MEDIUM] CWE-324 CVE-2025-48813: Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perfor
Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.
nvd
CVE-2026-20928P4MEDIUMCVSS 4.6fixed in 10.0.20348.5020≥ 10.0.20348.0, < 10.0.20348.50202026-04-14
CVE-2026-20928 [MEDIUM] CWE-212 CVE-2026-20928: Improper removal of sensitive information before storage or transfer in Windows Recovery Environment
Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2022-21918P4MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.4692022-01-11
CVE-2022-21918 [MEDIUM] CVE-2022-21918: DirectX Graphics Kernel File Denial of Service Vulnerability
DirectX Graphics Kernel File Denial of Service Vulnerability
nvd
CVE-2024-38027P4MEDIUMCVSS 6.5fixed in 10.0.20348.2582≥ 10.0.20348.0, < 10.0.20348.25822024-07-09
CVE-2024-38027 [MEDIUM] CWE-400 CVE-2024-38027: Windows Line Printer Daemon Service Denial of Service Vulnerability
Windows Line Printer Daemon Service Denial of Service Vulnerability
nvd
CVE-2023-35331P4MEDIUMCVSS 6.5≥ 10.0.20348.0, < 10.0.20348.18502023-07-11
CVE-2023-35331 [MEDIUM] CVE-2023-35331: Windows Local Security Authority (LSA) Denial of Service Vulnerability
Windows Local Security Authority (LSA) Denial of Service Vulnerability
nvd