Microsoft Windows Server 2022 vulnerabilities
3,303 known vulnerabilities affecting microsoft/windows_server_2022.
Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
136
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14
Vulnerabilities
Page 68 of 166
CVE-2026-27910P3HIGHCVSS 7.8fixed in 10.0.20348.5020≥ 10.0.20348.0, < 10.0.20348.50202026-04-14
CVE-2026-27910 [HIGH] CWE-280 CVE-2026-27910: Improper handling of insufficient permissions or privileges in Windows Installer allows an authorize
Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54989P3HIGHCVSS 7.8fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-54989 [HIGH] CWE-416 CVE-2026-54989: Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attack
Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32165P3HIGHCVSS 7.8fixed in 10.0.20348.5020≥ 10.0.20348.0, < 10.0.20348.50202026-04-14
CVE-2026-32165 [HIGH] CWE-362 CVE-2026-32165: Use after free in Windows User Interface Core allows an authorized attacker to elevate privileges lo
Use after free in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32164P3HIGHCVSS 7.8fixed in 10.0.20348.5020≥ 10.0.20348.0, < 10.0.20348.50202026-04-14
CVE-2026-32164 [HIGH] CWE-362 CVE-2026-32164: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32163P3HIGHCVSS 7.8fixed in 10.0.20348.5020≥ 10.0.20348.0, < 10.0.20348.50202026-04-14
CVE-2026-32163 [HIGH] CWE-362 CVE-2026-32163: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26172P3HIGHCVSS 7.8fixed in 10.0.20348.5020≥ 10.0.20348.0, < 10.0.20348.50202026-04-14
CVE-2026-26172 [HIGH] CWE-362 CVE-2026-26172: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-27911P3HIGHCVSS 7.8fixed in 10.0.20348.5020≥ 10.0.20348.0, < 10.0.20348.50202026-04-14
CVE-2026-27911 [HIGH] CWE-362 CVE-2026-27911: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49787P3HIGHCVSS 7.5fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-49787 [HIGH] CWE-770 CVE-2026-49787: Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized atta
Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-54119P3HIGHCVSS 7.5fixed in 10.0.20348.5386≥ 10.0.20348.0, < 10.0.20348.53862026-07-14
CVE-2026-54119 [HIGH] CWE-835 CVE-2026-54119: Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unautho
Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.
nvd
CVE-2024-29066P3HIGHCVSS 7.2fixed in 10.0.20348.2402≥ 10.0.20348.0, < 10.0.20348.24022024-04-09
CVE-2024-29066 [HIGH] CWE-367 CVE-2024-29066: Windows Distributed File System (DFS) Remote Code Execution Vulnerability
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
nvd
CVE-2023-35350P3HIGHCVSS 7.2≥ 10.0.20348.0, < 10.0.20348.18502023-07-11
CVE-2023-35350 [HIGH] CWE-122 CVE-2023-35350: Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
nvd
CVE-2023-32033P3HIGHCVSS 7.2≥ 10.0.20348.0, < 10.0.20348.18502023-07-11
CVE-2023-32033 [HIGH] CWE-416 CVE-2023-32033: Microsoft Failover Cluster Remote Code Execution Vulnerability
Microsoft Failover Cluster Remote Code Execution Vulnerability
nvd
CVE-2022-44675P3HIGHCVSS 7.8≥ 10.0.20348.0, < 10.0.20348.13662022-12-13
CVE-2022-44675 [HIGH] CVE-2022-44675: Windows Bluetooth Driver Elevation of Privilege Vulnerability
Windows Bluetooth Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-50161P3HIGHCVSS 7.3fixed in 10.0.20348.3989≥ 10.0.20348.0, < 10.0.20348.40522025-08-12
CVE-2025-50161 [HIGH] CWE-122 CVE-2025-50161: Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privile
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-62565P3HIGHCVSS 7.3fixed in 10.0.20348.4467≥ 10.0.20348.0, < 10.0.20348.45292025-12-09
CVE-2025-62565 [HIGH] CWE-416 CVE-2025-62565: Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-30147P3HIGHCVSS 7.8≥ 10.0.20348.0, < 10.0.20348.7702022-06-15
CVE-2022-30147 [HIGH] CVE-2022-30147: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2022-34699P3HIGHCVSS 7.8≥ 10.0.20348.0, < 10.0.20348.8872022-08-09
CVE-2022-34699 [HIGH] CWE-269 CVE-2022-34699: Windows Win32k Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
nvd
CVE-2022-24507P3HIGHCVSS 7.8≥ 10.0.20348.0, < 10.0.20348.5872022-03-09
CVE-2022-24507 [HIGH] CVE-2022-24507: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd
CVE-2023-24912P3HIGHCVSS 7.8≥ 10.0.20348.0, < 10.0.20348.16682023-04-11
CVE-2023-24912 [HIGH] CWE-122 CVE-2023-24912: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2022-21989P3HIGHCVSS 7.8≥ 10.0.20348.0, < 10.0.20348.5242022-02-09
CVE-2022-21989 [HIGH] CVE-2022-21989: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd