cbcvebase.

Microsoft Windows Server 2022 vulnerabilities

3,303 known vulnerabilities affecting microsoft/windows_server_2022.

Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
135
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14

Vulnerabilities

Page 6 of 166
CVE-2022-21882HIGHCVSS 7.0KEVPoC≥ 10.0.20348.0, < 10.0.20348.4692022-01-11
CVE-2022-21882 [HIGH] Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability
cvelistv5
CVE-2023-21768P1HIGHCVSS 7.8ExploitedPoC≥ 10.0.20348.0, < 10.0.20348.14872023-01-10
CVE-2023-21768 [HIGH] CWE-822 CVE-2023-21768: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd
CVE-2025-24071P1MEDIUMCVSS 6.5ExploitedPoCfixed in 10.0.20348.3328≥ 10.0.20348.0, < 10.0.20348.33282025-03-11
CVE-2025-24071 [MEDIUM] CWE-200 CVE-2025-24071: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauth Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2024-30090P1HIGHCVSS 7.0ExploitedPoCRansomwarefixed in 10.0.20348.2522≥ 10.0.20348.0, < 10.0.20348.25272024-06-11
CVE-2024-30090 [HIGH] CWE-822 CVE-2024-30090: Microsoft Streaming Service Elevation of Privilege Vulnerability Microsoft Streaming Service Elevation of Privilege Vulnerability
nvd
CVE-2022-24481P2HIGHCVSS 7.8ExploitedPoC≥ 10.0.20348.0, < 10.0.20348.6432022-04-15
CVE-2022-24481 [HIGH] CVE-2022-24481: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-26229P1HIGHCVSS 7.8ExploitedPoCfixed in 10.0.20348.2402≥ 10.0.20348.0, < 10.0.20348.24022024-04-09
CVE-2024-26229 [HIGH] CWE-122 CVE-2024-26229: Windows CSC Service Elevation of Privilege Vulnerability Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2024-38112HIGHCVSS 7.5KEV≥ 10.0.20348.0, < 10.0.20348.25822024-07-09
CVE-2024-38112 [HIGH] CWE-451 Windows MSHTML Platform Spoofing Vulnerability Windows MSHTML Platform Spoofing Vulnerability Windows MSHTML Platform Spoofing Vulnerability
cvelistv5
CVE-2024-43461HIGHCVSS 8.8KEV≥ 10.0.20348.0, < 10.0.20348.27002024-09-10
CVE-2024-43461 [HIGH] CWE-451 Windows MSHTML Platform Spoofing Vulnerability Windows MSHTML Platform Spoofing Vulnerability Windows MSHTML Platform Spoofing Vulnerability
cvelistv5
CVE-2024-38178HIGHCVSS 7.5KEV≥ 10.0.20348.0, < 10.0.20348.26552024-08-13
CVE-2024-38178 [HIGH] CWE-843 Scripting Engine Memory Corruption Vulnerability Scripting Engine Memory Corruption Vulnerability Scripting Engine Memory Corruption Vulnerability
cvelistv5
CVE-2024-43573MEDIUMCVSS 6.5KEV≥ 10.0.20348.0, < 10.0.20348.27622024-10-08
CVE-2024-43573 [MEDIUM] CWE-79 Windows MSHTML Platform Spoofing Vulnerability Windows MSHTML Platform Spoofing Vulnerability Windows MSHTML Platform Spoofing Vulnerability
cvelistv5
CVE-2024-21407P1HIGHCVSS 8.1ExploitedRansomwarefixed in 10.0.20348.2333≥ 10.0.20348.0, < 10.0.20348.23402024-03-12
CVE-2024-21407 [HIGH] CWE-416 CVE-2024-21407: Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2022-26925HIGHCVSS 8.1KEVRansomware≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-26925 [HIGH] Windows LSA Spoofing Vulnerability Windows LSA Spoofing Vulnerability Windows LSA Spoofing Vulnerability
cvelistv5
CVE-2021-41357HIGHCVSS 7.8KEV≥ 10.0.0, < 10.0.20348.2882021-10-13
CVE-2021-41357 [HIGH] Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability
cvelistv5
CVE-2021-40450HIGHCVSS 7.8KEV≥ 10.0.0, < 10.0.20348.2882021-10-13
CVE-2021-40450 [HIGH] Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability
cvelistv5
CVE-2021-43207P1HIGHCVSS 7.8ExploitedRansomware≥ 10.0.0, < 10.0.20348.4052021-12-15
CVE-2021-43207 [HIGH] CVE-2021-43207: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-35803P2HIGHCVSS 7.8Exploited≥ 10.0.20348.0, < 10.0.20348.10062022-09-13
CVE-2022-35803 [HIGH] CVE-2022-35803: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2026-25187P1HIGHCVSS 7.8Exploitedfixed in 10.0.20348.4830≥ 10.0.20348.0, < 10.0.20348.48932026-03-10
CVE-2026-25187 [HIGH] CWE-59 CVE-2026-25187: Improper link resolution before file access ('link following') in Winlogon allows an authorized atta Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-45586P2HIGHCVSS 7.8Exploitedfixed in 10.0.20348.5256≥ 10.0.20348.0, < 10.0.20348.52562026-06-09
CVE-2026-45586 [HIGH] CWE-59 CVE-2026-45586: Improper link resolution before file access ('link following') in Windows Collaborative Translation Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-21447P2HIGHCVSS 7.8Exploitedfixed in 10.0.20348.2402≥ 10.0.20348.0, < 10.0.20348.24022024-04-09
CVE-2024-21447 [HIGH] CWE-59 CVE-2024-21447: Windows Authentication Elevation of Privilege Vulnerability Windows Authentication Elevation of Privilege Vulnerability
nvd
CVE-2024-38196P2HIGHCVSS 7.8Exploitedfixed in 10.0.20348.2655≥ 10.0.20348.0, < 10.0.20348.26552024-08-13
CVE-2024-38196 [HIGH] CWE-20 CVE-2024-38196: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
Microsoft Windows Server 2022 vulnerabilities | cvebase