Microsoft Windows Server 2022 vulnerabilities
3,303 known vulnerabilities affecting microsoft/windows_server_2022.
Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
135
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14
Vulnerabilities
Page 21 of 166
CVE-2023-24884P3HIGHCVSS 8.8≥ 10.0.20348.0, < 10.0.20348.16682023-04-11
CVE-2023-24884 [HIGH] CWE-681 CVE-2023-24884: Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
nvd
CVE-2023-28243P3HIGHCVSS 8.8≥ 10.0.20348.0, < 10.0.20348.16682023-04-11
CVE-2023-28243 [HIGH] CWE-843 CVE-2023-28243: Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
nvd
CVE-2025-21223P3HIGHCVSS 8.8fixed in 10.0.20348.3091≥ 10.0.20348.0, < 10.0.20348.30912025-01-14
CVE-2025-21223 [HIGH] CWE-122 CVE-2025-21223: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2024-43628P3HIGHCVSS 8.8fixed in 10.0.20348.2849≥ 10.0.20348.0, < 10.0.20348.28492024-11-12
CVE-2024-43628 [HIGH] CWE-190 CVE-2024-43628: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2024-43635P3HIGHCVSS 8.8fixed in 10.0.20348.2849≥ 10.0.20348.0, < 10.0.20348.28492024-11-12
CVE-2024-43635 [HIGH] CWE-190 CVE-2024-43635: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2024-43627P3HIGHCVSS 8.8fixed in 10.0.20348.2819≥ 10.0.20348.0, < 10.0.20348.28492024-11-12
CVE-2024-43627 [HIGH] CWE-122 CVE-2024-43627: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2023-35303P3HIGHCVSS 8.8≥ 10.0.20348.0, < 10.0.20348.18502023-07-11
CVE-2023-35303 [HIGH] CWE-20 CVE-2023-35303: USB Audio Class System Driver Remote Code Execution Vulnerability
USB Audio Class System Driver Remote Code Execution Vulnerability
nvd
CVE-2023-35302P3HIGHCVSS 8.8≥ 10.0.20348.0, < 10.0.20348.18502023-07-11
CVE-2023-35302 [HIGH] CWE-122 CVE-2023-35302: Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
nvd
CVE-2023-35300P3HIGHCVSS 8.8≥ 10.0.20348.0, < 10.0.20348.18502023-07-11
CVE-2023-35300 [HIGH] CWE-416 CVE-2023-35300: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2025-62549P3HIGHCVSS 8.8fixed in 10.0.20348.4467≥ 10.0.20348.0, < 10.0.20348.45292025-12-09
CVE-2025-62549 [HIGH] CWE-822 CVE-2025-62549: Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthor
Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-47289P3HIGHCVSS 8.8fixed in 10.0.20348.5256≥ 10.0.20348.0, < 10.0.20348.52562026-06-09
CVE-2026-47289 [HIGH] CWE-122 CVE-2026-47289: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-29840P3HIGHCVSS 8.8fixed in 10.0.20348.3692≥ 10.0.20348.0, < 10.0.20348.36922025-05-13
CVE-2025-29840 [HIGH] CWE-121 CVE-2025-29840: Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a
Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-49669P3HIGHCVSS 8.8fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-49669 [HIGH] CWE-122 CVE-2025-49669: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-49668P3HIGHCVSS 8.8fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-49668 [HIGH] CWE-122 CVE-2025-49668: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-49673P3HIGHCVSS 8.8fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-49673 [HIGH] CWE-122 CVE-2025-49673: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-49674P3HIGHCVSS 8.8fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-49674 [HIGH] CWE-122 CVE-2025-49674: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-49663P3HIGHCVSS 8.8fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-49663 [HIGH] CWE-122 CVE-2025-49663: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-49753P3HIGHCVSS 8.8fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-49753 [HIGH] CWE-122 CVE-2025-49753: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-58718P3HIGHCVSS 8.8fixed in 10.0.20348.4294≥ 10.0.20348.0, < 10.0.20348.42942025-10-14
CVE-2025-58718 [HIGH] CWE-416 CVE-2025-58718: Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-49729P3HIGHCVSS 8.8fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-49729 [HIGH] CWE-122 CVE-2025-49729: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd