Microsoft Windows Server 2022 vulnerabilities
3,303 known vulnerabilities affecting microsoft/windows_server_2022.
Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
135
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14
Vulnerabilities
Page 16 of 166
CVE-2024-30078P3HIGHCVSS 8.8fixed in 10.0.20348.2522≥ 10.0.20348.0, < 10.0.20348.25272024-06-11
CVE-2024-30078 [HIGH] CWE-20 CVE-2024-30078: Windows Wi-Fi Driver Remote Code Execution Vulnerability
Windows Wi-Fi Driver Remote Code Execution Vulnerability
nvd
CVE-2025-33070P3HIGHCVSS 8.1fixed in 10.0.20348.3745≥ 10.0.20348.0, < 10.0.20348.38072025-06-10
CVE-2025-33070 [HIGH] CWE-908 CVE-2025-33070: Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privile
Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2024-38240P3CRITICALCVSS 9.8fixed in 10.0.20348.2700≥ 10.0.20348.0, < 10.0.20348.27002024-09-10
CVE-2024-38240 [CRITICAL] CWE-125 CVE-2024-38240: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
nvd
CVE-2026-49798P3CRITICALCVSS 9.3fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-49798 [CRITICAL] CWE-416 CVE-2026-49798: Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2025-26645P3HIGHCVSS 8.8fixed in 10.0.20348.3270fixed in 10.0.20348.3328+1 more2025-03-11
CVE-2025-26645 [HIGH] CWE-23 CVE-2025-26645: Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code ove
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-49164P3CRITICALCVSS 9.8fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-49164 [CRITICAL] CWE-122 CVE-2026-49164: Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to ex
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
nvd
CVE-2022-35841P3HIGHCVSS 8.8≥ 10.0.20348.0, < 10.0.20348.10062022-09-13
CVE-2022-35841 [HIGH] CVE-2022-35841: Windows Enterprise App Management Service Remote Code Execution Vulnerability
Windows Enterprise App Management Service Remote Code Execution Vulnerability
nvd
CVE-2025-53722P3HIGHCVSS 7.5fixed in 10.0.20348.3989≥ 10.0.20348.0, < 10.0.20348.40522025-08-12
CVE-2025-53722 [HIGH] CWE-400 CVE-2025-53722: Uncontrolled resource consumption in Windows Remote Desktop Services allows an unauthorized attacker
Uncontrolled resource consumption in Windows Remote Desktop Services allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50380P3CRITICALCVSS 9.6fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-50380 [CRITICAL] CWE-122 CVE-2026-50380: Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a ne
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-20678P3HIGHCVSS 8.8fixed in 10.0.20348.2402≥ 10.0.20348.0, < 10.0.20348.24022024-04-09
CVE-2024-20678 [HIGH] CWE-843 CVE-2024-20678: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2022-29137P3HIGHCVSS 8.8≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-29137 [HIGH] CVE-2022-29137: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-22014P3HIGHCVSS 8.8≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-22014 [HIGH] CVE-2022-22014: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-22013P3HIGHCVSS 8.8≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-22013 [HIGH] CVE-2022-22013: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2023-38148P3HIGHCVSS 8.8fixed in 10.0.20348.1960≥ 10.0.20348.0, < 10.0.20348.19702023-09-12
CVE-2023-38148 [HIGH] CWE-121 CVE-2023-38148: Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
nvd
CVE-2023-36423P3HIGHCVSS 8.8≥ 10.0.20348.0, < 10.0.20348.21132023-11-14
CVE-2023-36423 [HIGH] CWE-122 CVE-2023-36423: Microsoft Remote Registry Service Remote Code Execution Vulnerability
Microsoft Remote Registry Service Remote Code Execution Vulnerability
nvd
CVE-2026-20840P3HIGHCVSS 7.8fixed in 10.0.20348.4648≥ 10.0.20348.0, < 10.0.20348.46482026-01-13
CVE-2026-20840 [HIGH] CWE-122 CVE-2026-20840: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2025-59295P3HIGHCVSS 8.8fixed in 10.0.20348.4294≥ 10.0.20348.0, < 10.0.20348.42942025-10-14
CVE-2025-59295 [HIGH] CWE-122 CVE-2025-59295: Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over
Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-24051P3HIGHCVSS 8.8fixed in 10.0.20348.3270fixed in 10.0.20348.3328+1 more2025-03-11
CVE-2025-24051 [HIGH] CWE-122 CVE-2025-24051: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2023-35641P3HIGHCVSS 8.8≥ 10.0.20348.0, < 10.0.20348.21592023-12-12
CVE-2023-35641 [HIGH] CWE-682 CVE-2023-35641: Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
nvd
CVE-2025-49757P3HIGHCVSS 8.8fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-08-12
CVE-2025-49757 [HIGH] CWE-122 CVE-2025-49757: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd