Microsoft Windows Server 2022 vulnerabilities
3,303 known vulnerabilities affecting microsoft/windows_server_2022.
Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
135
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14
Vulnerabilities
Page 22 of 166
CVE-2026-40403P3HIGHCVSS 8.8fixed in 10.0.20348.5074≥ 10.0.20348.0, < 10.0.20348.51392026-05-12
CVE-2026-40403 [HIGH] CWE-122 CVE-2026-40403: Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code lo
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
nvd
CVE-2026-54982P3HIGHCVSS 8.8fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-54982 [HIGH] CWE-191 CVE-2026-54982: Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an una
Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.
nvd
CVE-2025-58722P3HIGHCVSS 7.8fixed in 10.0.20348.4294≥ 10.0.20348.0, < 10.0.20348.42942025-10-14
CVE-2025-58722 [HIGH] CWE-122 CVE-2025-58722: Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locall
Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20860P3HIGHCVSS 7.8fixed in 10.0.20348.4648≥ 10.0.20348.0, < 10.0.20348.46482026-01-13
CVE-2026-20860 [HIGH] CWE-843 CVE-2026-20860: Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver f
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56188P3HIGHCVSS 8.1fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-56188 [HIGH] CWE-362 CVE-2026-56188: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-47984P3HIGHCVSS 7.5fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-47984 [HIGH] CWE-693 CVE-2025-47984: Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information
Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-50686P3HIGHCVSS 8.1fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-50686 [HIGH] CWE-843 CVE-2026-50686: Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized
Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-62452P3HIGHCVSS 8.0fixed in 10.0.20348.4346≥ 10.0.20348.0, < 10.0.20348.44052025-11-11
CVE-2025-62452 [HIGH] CWE-122 CVE-2025-62452: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
nvd
CVE-2025-60715P3HIGHCVSS 8.0fixed in 10.0.20348.4346≥ 10.0.20348.0, < 10.0.20348.44052025-11-11
CVE-2025-60715 [HIGH] CWE-122 CVE-2025-60715: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
nvd
CVE-2020-17042P3HIGHCVSS 8.8≥ 10.0.0, < 10.0.20348.2700≥ 10.0.0, < 10.0.20348.26952020-11-11
CVE-2020-17042 [HIGH] CVE-2020-17042: Windows Print Spooler Remote Code Execution Vulnerability
Windows Print Spooler Remote Code Execution Vulnerability
nvd
CVE-2023-36434P3CRITICALCVSS 9.8≥ 10.0.20348.0, < 10.0.20348.20312023-10-10
CVE-2023-36434 [CRITICAL] CWE-307 CVE-2023-36434: Windows IIS Server Elevation of Privilege Vulnerability
Windows IIS Server Elevation of Privilege Vulnerability
nvd
CVE-2026-42980P3HIGHCVSS 7.8fixed in 10.0.20348.5256≥ 10.0.20348.0, < 10.0.20348.52562026-06-09
CVE-2026-42980 [HIGH] CWE-122 CVE-2026-42980: Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elev
Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-22029P3HIGHCVSS 8.1≥ 10.0.20348.0, < 10.0.20348.8252022-07-12
CVE-2022-22029 [HIGH] CVE-2022-22029: Windows Network File System Remote Code Execution Vulnerability
Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2022-21922P3HIGHCVSS 8.8≥ 10.0.20348.0, < 10.0.20348.4692022-01-11
CVE-2022-21922 [HIGH] CVE-2022-21922: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2023-35381P3HIGHCVSS 8.8≥ 10.0.20348.0, < 10.0.20348.19062023-08-08
CVE-2023-35381 [HIGH] CWE-190 CVE-2023-35381: Windows Fax Service Remote Code Execution Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2023-21727P3HIGHCVSS 8.8≥ 10.0.20348.0, < 10.0.20348.16682023-04-11
CVE-2023-21727 [HIGH] CWE-122 CVE-2023-21727: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2024-38128P3HIGHCVSS 8.8fixed in 10.0.20348.2655≥ 10.0.20348.0, < 10.0.20348.26552024-08-13
CVE-2024-38128 [HIGH] CWE-190 CVE-2024-38128: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-38121P3HIGHCVSS 8.8fixed in 10.0.20348.2655≥ 10.0.20348.0, < 10.0.20348.26552024-08-13
CVE-2024-38121 [HIGH] CWE-122 CVE-2024-38121: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-38115P3HIGHCVSS 8.8fixed in 10.0.20348.2655≥ 10.0.20348.0, < 10.0.20348.26552024-08-13
CVE-2024-38115 [HIGH] CWE-122 CVE-2024-38115: Windows IP Routing Management Snapin Remote Code Execution Vulnerability
Windows IP Routing Management Snapin Remote Code Execution Vulnerability
nvd
CVE-2024-38130P3HIGHCVSS 8.8fixed in 10.0.20348.2655≥ 10.0.20348.0, < 10.0.20348.26552024-08-13
CVE-2024-38130 [HIGH] CWE-122 CVE-2024-38130: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd