cbcvebase.

Microsoft Windows Server 2022 vulnerabilities

3,303 known vulnerabilities affecting microsoft/windows_server_2022.

Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
135
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14

Vulnerabilities

Page 7 of 166
CVE-2023-21554P1CRITICALCVSS 9.8PoC≥ 10.0.20348.0, < 10.0.20348.16682023-04-11
CVE-2023-21554 [CRITICAL] CWE-20 CVE-2023-21554: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2024-38100P2HIGHCVSS 7.8Exploitedfixed in 10.0.20348.2582≥ 10.0.20348.0, < 10.0.20348.25822024-07-09
CVE-2024-38100 [HIGH] CWE-284 CVE-2024-38100: Windows File Explorer Elevation of Privilege Vulnerability Windows File Explorer Elevation of Privilege Vulnerability
nvd
CVE-2026-20931P2HIGHCVSS 8.0Exploitedfixed in 10.0.20348.4648≥ 10.0.20348.0, < 10.0.20348.46482026-01-13
CVE-2026-20931 [HIGH] CWE-73 CVE-2026-20931: External control of file name or path in Windows Telephony Service allows an authorized attacker to External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.
nvd
CVE-2025-24061P2HIGHCVSS 7.8Exploitedfixed in 10.0.20348.3270≥ 10.0.20348.0, < 10.0.20348.33282025-03-11
CVE-2025-24061 [HIGH] CWE-693 CVE-2025-24061: Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to by Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally.
nvd
CVE-2023-29324P2MEDIUMCVSS 6.5Exploited≥ 10.0.20348.0, < 10.0.20348.17262023-05-09
CVE-2023-29324 [MEDIUM] CWE-73 CVE-2023-29324: Windows MSHTML Platform Security Feature Bypass Vulnerability Windows MSHTML Platform Security Feature Bypass Vulnerability
nvd
CVE-2023-28218P2HIGHCVSS 7.0Exploited≥ 10.0.20348.0, < 10.0.20348.16682023-04-11
CVE-2023-28218 [HIGH] CWE-122 CVE-2023-28218: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd
CVE-2022-30170P2HIGHCVSS 7.3Exploited≥ 10.0.20348.0, < 10.0.20348.10062022-09-13
CVE-2022-30170 [HIGH] CVE-2022-30170: Windows Credential Roaming Service Elevation of Privilege Vulnerability Windows Credential Roaming Service Elevation of Privilege Vulnerability
nvd
CVE-2024-38063P1CRITICALCVSS 9.8PoCfixed in 10.0.20348.2655≥ 10.0.20348.0, < 10.0.20348.27002024-08-13
CVE-2024-38063 [CRITICAL] CWE-191 CVE-2024-38063: Windows TCP/IP Remote Code Execution Vulnerability Windows TCP/IP Remote Code Execution Vulnerability
nvd
CVE-2022-21874P2CRITICALCVSS 9.8Exploited≥ 10.0.20348.0, < 10.0.20348.4692022-01-11
CVE-2022-21874 [CRITICAL] CVE-2022-21874: Windows Security Center API Remote Code Execution Vulnerability Windows Security Center API Remote Code Execution Vulnerability
nvd
CVE-2022-21898P3CRITICALCVSS 9.8Exploited≥ 10.0.20348.0, < 10.0.20348.4692022-01-11
CVE-2022-21898 [CRITICAL] CVE-2022-21898: DirectX Graphics Kernel Remote Code Execution Vulnerability DirectX Graphics Kernel Remote Code Execution Vulnerability
nvd
CVE-2023-24941P2CRITICALCVSS 9.8≥ 10.0.20348.0, < 10.0.20348.17262023-05-09
CVE-2023-24941 [CRITICAL] CWE-908 CVE-2023-24941: Windows Network File System Remote Code Execution Vulnerability Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2025-21293P2HIGHCVSS 8.8PoCfixed in 10.0.20348.3091≥ 10.0.20348.0, < 10.0.20348.30912025-01-14
CVE-2025-21293 [HIGH] CWE-284 CVE-2025-21293: Active Directory Domain Services Elevation of Privilege Vulnerability Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2024-38077P1CRITICALCVSS 9.8fixed in 10.0.20348.2582≥ 10.0.20348.0, < 10.0.20348.25822024-07-09
CVE-2024-38077 [CRITICAL] CWE-122 CVE-2024-38077: Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
nvd
CVE-2024-49112P1CRITICALCVSS 9.8fixed in 10.0.20348.2966≥ 10.0.20348.0, < 10.0.20348.29662024-12-12
CVE-2024-49112 [CRITICAL] CWE-190 CVE-2024-49112: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-34715P2CRITICALCVSS 9.8≥ 10.0.20348.0, < 10.0.20348.8872022-08-09
CVE-2022-34715 [CRITICAL] CWE-94 CVE-2022-34715: Windows Network File System Remote Code Execution Vulnerability Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2022-26937P2CRITICALCVSS 9.8≥ 10.0.20348.0, < 10.0.20348.7072022-05-10
CVE-2022-26937 [CRITICAL] CVE-2022-26937: Windows Network File System Remote Code Execution Vulnerability Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2023-38545P2CRITICALCVSS 9.8fixed in 10.0.20348.21132023-10-18
CVE-2023-38545 [CRITICAL] CWE-787 CVE-2023-38545: This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255 bytes. If the host name is detected to be longer, curl switches to local
nvd
CVE-2023-35628P2HIGHCVSS 8.1≥ 10.0.20348.0, < 10.0.20348.21592023-12-12
CVE-2023-35628 [HIGH] CWE-416 CVE-2023-35628: Windows MSHTML Platform Remote Code Execution Vulnerability Windows MSHTML Platform Remote Code Execution Vulnerability
nvd
CVE-2026-33824P2CRITICALCVSS 9.8fixed in 10.0.20348.5020≥ 10.0.20348.0, < 10.0.20348.50202026-04-14
CVE-2026-33824 [CRITICAL] CWE-415 CVE-2026-33824: Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
nvd
CVE-2022-34718P2CRITICALCVSS 9.8≥ 10.0.20348.0, < 10.0.20348.10062022-09-13
CVE-2022-34718 [CRITICAL] CVE-2022-34718: Windows TCP/IP Remote Code Execution Vulnerability Windows TCP/IP Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2022 vulnerabilities | cvebase