Microsoft Windows Server 2022 vulnerabilities
3,303 known vulnerabilities affecting microsoft/windows_server_2022.
Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
135
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14
Vulnerabilities
Page 7 of 166
CVE-2023-21554P1CRITICALCVSS 9.8PoC≥ 10.0.20348.0, < 10.0.20348.16682023-04-11
CVE-2023-21554 [CRITICAL] CWE-20 CVE-2023-21554: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2024-38100P2HIGHCVSS 7.8Exploitedfixed in 10.0.20348.2582≥ 10.0.20348.0, < 10.0.20348.25822024-07-09
CVE-2024-38100 [HIGH] CWE-284 CVE-2024-38100: Windows File Explorer Elevation of Privilege Vulnerability
Windows File Explorer Elevation of Privilege Vulnerability
nvd
CVE-2026-20931P2HIGHCVSS 8.0Exploitedfixed in 10.0.20348.4648≥ 10.0.20348.0, < 10.0.20348.46482026-01-13
CVE-2026-20931 [HIGH] CWE-73 CVE-2026-20931: External control of file name or path in Windows Telephony Service allows an authorized attacker to
External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.
nvd
CVE-2025-24061P2HIGHCVSS 7.8Exploitedfixed in 10.0.20348.3270≥ 10.0.20348.0, < 10.0.20348.33282025-03-11
CVE-2025-24061 [HIGH] CWE-693 CVE-2025-24061: Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to by
Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally.
nvd
CVE-2023-29324P2MEDIUMCVSS 6.5Exploited≥ 10.0.20348.0, < 10.0.20348.17262023-05-09
CVE-2023-29324 [MEDIUM] CWE-73 CVE-2023-29324: Windows MSHTML Platform Security Feature Bypass Vulnerability
Windows MSHTML Platform Security Feature Bypass Vulnerability
nvd
CVE-2023-28218P2HIGHCVSS 7.0Exploited≥ 10.0.20348.0, < 10.0.20348.16682023-04-11
CVE-2023-28218 [HIGH] CWE-122 CVE-2023-28218: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd
CVE-2022-30170P2HIGHCVSS 7.3Exploited≥ 10.0.20348.0, < 10.0.20348.10062022-09-13
CVE-2022-30170 [HIGH] CVE-2022-30170: Windows Credential Roaming Service Elevation of Privilege Vulnerability
Windows Credential Roaming Service Elevation of Privilege Vulnerability
nvd
CVE-2024-38063P1CRITICALCVSS 9.8PoCfixed in 10.0.20348.2655≥ 10.0.20348.0, < 10.0.20348.27002024-08-13
CVE-2024-38063 [CRITICAL] CWE-191 CVE-2024-38063: Windows TCP/IP Remote Code Execution Vulnerability
Windows TCP/IP Remote Code Execution Vulnerability
nvd
CVE-2022-21874P2CRITICALCVSS 9.8Exploited≥ 10.0.20348.0, < 10.0.20348.4692022-01-11
CVE-2022-21874 [CRITICAL] CVE-2022-21874: Windows Security Center API Remote Code Execution Vulnerability
Windows Security Center API Remote Code Execution Vulnerability
nvd
CVE-2022-21898P3CRITICALCVSS 9.8Exploited≥ 10.0.20348.0, < 10.0.20348.4692022-01-11
CVE-2022-21898 [CRITICAL] CVE-2022-21898: DirectX Graphics Kernel Remote Code Execution Vulnerability
DirectX Graphics Kernel Remote Code Execution Vulnerability
nvd
CVE-2023-24941P2CRITICALCVSS 9.8≥ 10.0.20348.0, < 10.0.20348.17262023-05-09
CVE-2023-24941 [CRITICAL] CWE-908 CVE-2023-24941: Windows Network File System Remote Code Execution Vulnerability
Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2025-21293P2HIGHCVSS 8.8PoCfixed in 10.0.20348.3091≥ 10.0.20348.0, < 10.0.20348.30912025-01-14
CVE-2025-21293 [HIGH] CWE-284 CVE-2025-21293: Active Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2024-38077P1CRITICALCVSS 9.8fixed in 10.0.20348.2582≥ 10.0.20348.0, < 10.0.20348.25822024-07-09
CVE-2024-38077 [CRITICAL] CWE-122 CVE-2024-38077: Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
nvd
CVE-2024-49112P1CRITICALCVSS 9.8fixed in 10.0.20348.2966≥ 10.0.20348.0, < 10.0.20348.29662024-12-12
CVE-2024-49112 [CRITICAL] CWE-190 CVE-2024-49112: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-34715P2CRITICALCVSS 9.8≥ 10.0.20348.0, < 10.0.20348.8872022-08-09
CVE-2022-34715 [CRITICAL] CWE-94 CVE-2022-34715: Windows Network File System Remote Code Execution Vulnerability
Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2022-26937P2CRITICALCVSS 9.8≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-26937 [CRITICAL] CVE-2022-26937: Windows Network File System Remote Code Execution Vulnerability
Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2023-38545P2CRITICALCVSS 9.8fixed in 10.0.20348.21132023-10-18
CVE-2023-38545 [CRITICAL] CWE-787 CVE-2023-38545: This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy
handshake.
When curl is asked to pass along the host name to the SOCKS5 proxy to allow
that to resolve the address instead of it getting done by curl itself, the
maximum length that host name can be is 255 bytes.
If the host name is detected to be longer, curl switches to local
nvd
CVE-2023-35628P2HIGHCVSS 8.1≥ 10.0.20348.0, < 10.0.20348.21592023-12-12
CVE-2023-35628 [HIGH] CWE-416 CVE-2023-35628: Windows MSHTML Platform Remote Code Execution Vulnerability
Windows MSHTML Platform Remote Code Execution Vulnerability
nvd
CVE-2026-33824P2CRITICALCVSS 9.8fixed in 10.0.20348.5020≥ 10.0.20348.0, < 10.0.20348.50202026-04-14
CVE-2026-33824 [CRITICAL] CWE-415 CVE-2026-33824: Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
nvd
CVE-2022-34718P2CRITICALCVSS 9.8≥ 10.0.20348.0, < 10.0.20348.10062022-09-13
CVE-2022-34718 [CRITICAL] CVE-2022-34718: Windows TCP/IP Remote Code Execution Vulnerability
Windows TCP/IP Remote Code Execution Vulnerability
nvd