cbcvebase.

Microsoft Windows Server 2022 vulnerabilities

3,303 known vulnerabilities affecting microsoft/windows_server_2022.

Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
136
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14

Vulnerabilities

Page 69 of 166
CVE-2022-37967P3HIGHCVSS 7.2≥ 10.0.20348.0, < 10.0.20348.20312022-11-09
CVE-2022-37967 [HIGH] CVE-2022-37967: Windows Kerberos Elevation of Privilege Vulnerability Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2024-21417P3HIGHCVSS 8.8fixed in 10.0.20348.2582≥ 10.0.20348.0, < 10.0.20348.25822024-07-10
CVE-2024-21417 [HIGH] CWE-862 CVE-2024-21417: Windows Text Services Framework Elevation of Privilege Vulnerability Windows Text Services Framework Elevation of Privilege Vulnerability
nvd
CVE-2025-48822P3HIGHCVSS 8.6fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-48822 [HIGH] CWE-125 CVE-2025-48822: Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50507P3MEDIUMCVSS 6.8fixed in 10.0.20348.5256≥ 10.0.20348.0, < 10.0.20348.52562026-06-09
CVE-2026-50507 [MEDIUM] CWE-306 CVE-2026-50507: Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2023-36723P3HIGHCVSS 7.8≥ 10.0.20348.0, < 10.0.20348.20312023-10-10
CVE-2023-36723 [HIGH] CWE-59 CVE-2023-36723: Windows Container Manager Service Elevation of Privilege Vulnerability Windows Container Manager Service Elevation of Privilege Vulnerability
nvd
CVE-2024-49019P3HIGHCVSS 7.8fixed in 10.0.20348.2849≥ 10.0.20348.0, < 10.0.20348.28492024-11-12
CVE-2024-49019 [HIGH] CWE-1390 CVE-2024-49019: Active Directory Certificate Services Elevation of Privilege Vulnerability Active Directory Certificate Services Elevation of Privilege Vulnerability
nvd
CVE-2024-20696P3HIGHCVSS 7.3fixed in 10.0.20348.2227≥ 10.0.20348.0, < 10.0.20348.22272024-01-09
CVE-2024-20696 [HIGH] CWE-122 CVE-2024-20696: Windows libarchive Remote Code Execution Vulnerability Windows libarchive Remote Code Execution Vulnerability
nvd
CVE-2022-35793P3HIGHCVSS 7.3≥ 10.0.20348.0, < 10.0.20348.8872022-08-09
CVE-2022-35793 [HIGH] CVE-2022-35793: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-26931P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-26931 [HIGH] CVE-2022-26931: Windows Kerberos Elevation of Privilege Vulnerability Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2024-38127P3HIGHCVSS 7.8fixed in 10.0.20348.2655≥ 10.0.20348.0, < 10.0.20348.26552024-08-13
CVE-2024-38127 [HIGH] CWE-126 CVE-2024-38127: Windows Hyper-V Elevation of Privilege Vulnerability Windows Hyper-V Elevation of Privilege Vulnerability
nvd
CVE-2024-38062P3HIGHCVSS 7.8fixed in 10.0.20348.2582≥ 10.0.20348.0, < 10.0.20348.25822024-07-09
CVE-2024-38062 [HIGH] CWE-125 CVE-2024-38062: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-30209P3HIGHCVSS 7.4≥ 10.0.20348.0, < 10.0.20348.8252022-07-12
CVE-2022-30209 [HIGH] CVE-2022-30209: Windows IIS Server Elevation of Privilege Vulnerability Windows IIS Server Elevation of Privilege Vulnerability
nvd
CVE-2025-27470P3HIGHCVSS 7.5fixed in 10.0.20348.3453≥ 10.0.20348.0, < 10.0.20348.34532025-04-08
CVE-2025-27470 [HIGH] CWE-400 CVE-2025-27470: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-26652P3HIGHCVSS 7.5fixed in 10.0.20348.3453≥ 10.0.20348.0, < 10.0.20348.34532025-04-08
CVE-2025-26652 [HIGH] CWE-400 CVE-2025-26652: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-27479P3HIGHCVSS 7.5fixed in 10.0.20348.3453≥ 10.0.20348.0, < 10.0.20348.34532025-04-08
CVE-2025-27479 [HIGH] CWE-410 CVE-2025-27479: Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-21174P3HIGHCVSS 7.5fixed in 10.0.20348.3453≥ 10.0.20348.0, < 10.0.20348.34532025-04-08
CVE-2025-21174 [HIGH] CWE-400 CVE-2025-21174: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-27486P3HIGHCVSS 7.5fixed in 10.0.20348.3453≥ 10.0.20348.0, < 10.0.20348.34532025-04-08
CVE-2025-27486 [HIGH] CWE-400 CVE-2025-27486: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-27485P3HIGHCVSS 7.5fixed in 10.0.20348.3453≥ 10.0.20348.0, < 10.0.20348.34532025-04-08
CVE-2025-27485 [HIGH] CWE-400 CVE-2025-27485: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-26680P3HIGHCVSS 7.5fixed in 10.0.20348.3453≥ 10.0.20348.0, < 10.0.20348.34532025-04-08
CVE-2025-26680 [HIGH] CWE-400 CVE-2025-26680: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2024-38245P3HIGHCVSS 7.8fixed in 10.0.20348.2700≥ 10.0.20348.0, < 10.0.20348.27002024-09-10
CVE-2024-38245 [HIGH] CWE-20 CVE-2024-38245: Kernel Streaming Service Driver Elevation of Privilege Vulnerability Kernel Streaming Service Driver Elevation of Privilege Vulnerability
nvd
Microsoft Windows Server 2022 vulnerabilities | cvebase