Microsoft Windows Server 2022 vulnerabilities
3,303 known vulnerabilities affecting microsoft/windows_server_2022.
Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
136
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14
Vulnerabilities
Page 70 of 166
CVE-2025-33050P3HIGHCVSS 7.5fixed in 10.0.20348.3745≥ 10.0.20348.0, < 10.0.20348.38072025-06-10
CVE-2025-33050 [HIGH] CWE-693 CVE-2025-33050: Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service
Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-32725P3HIGHCVSS 7.5fixed in 10.0.20348.3745≥ 10.0.20348.0, < 10.0.20348.38072025-06-10
CVE-2025-32725 [HIGH] CWE-693 CVE-2025-32725: Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service
Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-33068P3HIGHCVSS 7.5fixed in 10.0.20348.3745≥ 10.0.20348.0, < 10.0.20348.38072025-06-10
CVE-2025-33068 [HIGH] CWE-400 CVE-2025-33068: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-29812P3HIGHCVSS 7.8fixed in 10.0.20348.3453≥ 10.0.20348.0, < 10.0.20348.34532025-04-08
CVE-2025-29812 [HIGH] CWE-822 CVE-2025-29812: Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate priv
Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-21363P3HIGHCVSS 7.8fixed in 10.0.20348.2322≥ 10.0.20348.0, < 10.0.20348.23222024-02-13
CVE-2024-21363 [HIGH] CWE-843 CVE-2024-21363: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2026-20875P3HIGHCVSS 7.5fixed in 10.0.20348.4648≥ 10.0.20348.0, < 10.0.20348.46482026-01-13
CVE-2026-20875 [HIGH] CWE-476 CVE-2026-20875: Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an una
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2024-38243P3HIGHCVSS 7.8fixed in 10.0.20348.2700≥ 10.0.20348.0, < 10.0.20348.27002024-09-10
CVE-2024-38243 [HIGH] CWE-20 CVE-2024-38243: Kernel Streaming Service Driver Elevation of Privilege Vulnerability
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-38238P3HIGHCVSS 7.8fixed in 10.0.20348.2700≥ 10.0.20348.0, < 10.0.20348.27002024-09-10
CVE-2024-38238 [HIGH] CWE-122 CVE-2024-38238: Kernel Streaming Service Driver Elevation of Privilege Vulnerability
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-20682P3HIGHCVSS 7.8≥ 10.0.20348.0, < 10.0.20348.22272024-01-09
CVE-2024-20682 [HIGH] CWE-822 CVE-2024-20682: Windows Cryptographic Services Remote Code Execution Vulnerability
Windows Cryptographic Services Remote Code Execution Vulnerability
nvd
CVE-2024-38057P3HIGHCVSS 7.8fixed in 10.0.20348.2582≥ 10.0.20348.0, < 10.0.20348.25822024-07-09
CVE-2024-38057 [HIGH] CWE-125 CVE-2024-38057: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-33056P3HIGHCVSS 7.5fixed in 10.0.20348.3745≥ 10.0.20348.0, < 10.0.20348.38072025-06-10
CVE-2025-33056 [HIGH] CWE-284 CVE-2025-33056: Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized
Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2024-38134P3HIGHCVSS 7.8fixed in 10.0.20348.2655≥ 10.0.20348.0, < 10.0.20348.26552024-08-13
CVE-2024-38134 [HIGH] CWE-125 CVE-2024-38134: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-26677P3HIGHCVSS 7.5fixed in 10.0.20348.3692≥ 10.0.20348.0, < 10.0.20348.36922025-05-13
CVE-2025-26677 [HIGH] CWE-400 CVE-2025-26677: Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker
Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-21375P3HIGHCVSS 7.8fixed in 10.0.20348.3207≥ 10.0.20348.0, < 10.0.20348.32072025-02-11
CVE-2025-21375 [HIGH] CWE-20 CVE-2025-21375: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-49716P3HIGHCVSS 7.5fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-49716 [HIGH] CWE-400 CVE-2025-49716: Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny servic
Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-24044P3HIGHCVSS 7.8fixed in 10.0.20348.3270≥ 10.0.20348.0, < 10.0.20348.33282025-03-11
CVE-2025-24044 [HIGH] CWE-416 CVE-2025-24044: Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges
Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-26679P3HIGHCVSS 7.8fixed in 10.0.20348.3453≥ 10.0.20348.0, < 10.0.20348.34532025-04-08
CVE-2025-26679 [HIGH] CWE-416 CVE-2025-26679: Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges lo
Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-33075P3HIGHCVSS 7.8fixed in 10.0.20348.3745≥ 10.0.20348.0, < 10.0.20348.38072025-06-10
CVE-2025-33075 [HIGH] CWE-59 CVE-2025-33075: Improper link resolution before file access ('link following') in Windows Installer allows an author
Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-44812P3HIGHCVSS 7.8fixed in 10.0.20348.5256≥ 10.0.20348.0, < 10.0.20348.52562026-06-09
CVE-2026-44812 [HIGH] CWE-190 CVE-2026-44812: Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute c
Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-44803P3HIGHCVSS 7.8fixed in 10.0.20348.5256≥ 10.0.20348.0, < 10.0.20348.52562026-06-09
CVE-2026-44803 [HIGH] CWE-190 CVE-2026-44803: Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute c
Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
nvd