Microsoft Windows Server 2022 vulnerabilities
3,303 known vulnerabilities affecting microsoft/windows_server_2022.
Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
135
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14
Vulnerabilities
Page 6 of 166
CVE-2022-21882HIGHCVSS 7.0KEVPoC≥ 10.0.20348.0, < 10.0.20348.4692022-01-11
CVE-2022-21882 [HIGH] Win32k Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
cvelistv5
CVE-2023-21768P1HIGHCVSS 7.8ExploitedPoC≥ 10.0.20348.0, < 10.0.20348.14872023-01-10
CVE-2023-21768 [HIGH] CWE-822 CVE-2023-21768: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd
CVE-2025-24071P1MEDIUMCVSS 6.5ExploitedPoCfixed in 10.0.20348.3328≥ 10.0.20348.0, < 10.0.20348.33282025-03-11
CVE-2025-24071 [MEDIUM] CWE-200 CVE-2025-24071: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauth
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2024-30090P1HIGHCVSS 7.0ExploitedPoCRansomwarefixed in 10.0.20348.2522≥ 10.0.20348.0, < 10.0.20348.25272024-06-11
CVE-2024-30090 [HIGH] CWE-822 CVE-2024-30090: Microsoft Streaming Service Elevation of Privilege Vulnerability
Microsoft Streaming Service Elevation of Privilege Vulnerability
nvd
CVE-2022-24481P2HIGHCVSS 7.8ExploitedPoC≥ 10.0.20348.0, < 10.0.20348.6432022-04-15
CVE-2022-24481 [HIGH] CVE-2022-24481: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-26229P1HIGHCVSS 7.8ExploitedPoCfixed in 10.0.20348.2402≥ 10.0.20348.0, < 10.0.20348.24022024-04-09
CVE-2024-26229 [HIGH] CWE-122 CVE-2024-26229: Windows CSC Service Elevation of Privilege Vulnerability
Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2024-38112HIGHCVSS 7.5KEV≥ 10.0.20348.0, < 10.0.20348.25822024-07-09
CVE-2024-38112 [HIGH] CWE-451 Windows MSHTML Platform Spoofing Vulnerability
Windows MSHTML Platform Spoofing Vulnerability
Windows MSHTML Platform Spoofing Vulnerability
cvelistv5
CVE-2024-43461HIGHCVSS 8.8KEV≥ 10.0.20348.0, < 10.0.20348.27002024-09-10
CVE-2024-43461 [HIGH] CWE-451 Windows MSHTML Platform Spoofing Vulnerability
Windows MSHTML Platform Spoofing Vulnerability
Windows MSHTML Platform Spoofing Vulnerability
cvelistv5
CVE-2024-38178HIGHCVSS 7.5KEV≥ 10.0.20348.0, < 10.0.20348.26552024-08-13
CVE-2024-38178 [HIGH] CWE-843 Scripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
cvelistv5
CVE-2024-43573MEDIUMCVSS 6.5KEV≥ 10.0.20348.0, < 10.0.20348.27622024-10-08
CVE-2024-43573 [MEDIUM] CWE-79 Windows MSHTML Platform Spoofing Vulnerability
Windows MSHTML Platform Spoofing Vulnerability
Windows MSHTML Platform Spoofing Vulnerability
cvelistv5
CVE-2024-21407P1HIGHCVSS 8.1ExploitedRansomwarefixed in 10.0.20348.2333≥ 10.0.20348.0, < 10.0.20348.23402024-03-12
CVE-2024-21407 [HIGH] CWE-416 CVE-2024-21407: Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2022-26925HIGHCVSS 8.1KEVRansomware≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-26925 [HIGH] Windows LSA Spoofing Vulnerability
Windows LSA Spoofing Vulnerability
Windows LSA Spoofing Vulnerability
cvelistv5
CVE-2021-41357HIGHCVSS 7.8KEV≥ 10.0.0, < 10.0.20348.2882021-10-13
CVE-2021-41357 [HIGH] Win32k Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
cvelistv5
CVE-2021-40450HIGHCVSS 7.8KEV≥ 10.0.0, < 10.0.20348.2882021-10-13
CVE-2021-40450 [HIGH] Win32k Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
cvelistv5
CVE-2021-43207P1HIGHCVSS 7.8ExploitedRansomware≥ 10.0.0, < 10.0.20348.4052021-12-15
CVE-2021-43207 [HIGH] CVE-2021-43207: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-35803P2HIGHCVSS 7.8Exploited≥ 10.0.20348.0, < 10.0.20348.10062022-09-13
CVE-2022-35803 [HIGH] CVE-2022-35803: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2026-25187P1HIGHCVSS 7.8Exploitedfixed in 10.0.20348.4830≥ 10.0.20348.0, < 10.0.20348.48932026-03-10
CVE-2026-25187 [HIGH] CWE-59 CVE-2026-25187: Improper link resolution before file access ('link following') in Winlogon allows an authorized atta
Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-45586P2HIGHCVSS 7.8Exploitedfixed in 10.0.20348.5256≥ 10.0.20348.0, < 10.0.20348.52562026-06-09
CVE-2026-45586 [HIGH] CWE-59 CVE-2026-45586: Improper link resolution before file access ('link following') in Windows Collaborative Translation
Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-21447P2HIGHCVSS 7.8Exploitedfixed in 10.0.20348.2402≥ 10.0.20348.0, < 10.0.20348.24022024-04-09
CVE-2024-21447 [HIGH] CWE-59 CVE-2024-21447: Windows Authentication Elevation of Privilege Vulnerability
Windows Authentication Elevation of Privilege Vulnerability
nvd
CVE-2024-38196P2HIGHCVSS 7.8Exploitedfixed in 10.0.20348.2655≥ 10.0.20348.0, < 10.0.20348.26552024-08-13
CVE-2024-38196 [HIGH] CWE-20 CVE-2024-38196: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd