Microsoft Windows Server 2022 vulnerabilities
3,303 known vulnerabilities affecting microsoft/windows_server_2022.
Total CVEs
3,303
CISA KEV
104
actively exploited
Public exploits
75
Exploited in wild
136
Severity breakdown
CRITICAL99HIGH2369MEDIUM821LOW14
Vulnerabilities
Page 79 of 166
CVE-2022-24485P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.6432022-04-15
CVE-2022-24485 [HIGH] CVE-2022-24485: Win32 File Enumeration Remote Code Execution Vulnerability
Win32 File Enumeration Remote Code Execution Vulnerability
nvd
CVE-2024-38261P3HIGHCVSS 7.8fixed in 10.0.20348.2762≥ 10.0.20348.0, < 10.0.20348.27622024-10-08
CVE-2024-38261 [HIGH] CWE-20 CVE-2024-38261: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-38186P3HIGHCVSS 7.8fixed in 10.0.20348.2582≥ 10.0.20348.0, < 10.0.20348.25822024-08-13
CVE-2024-38186 [HIGH] CWE-367 CVE-2024-38186: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-21434P3HIGHCVSS 7.8fixed in 10.0.20348.2333≥ 10.0.20348.0, < 10.0.20348.23402024-03-12
CVE-2024-21434 [HIGH] CWE-197 CVE-2024-21434: Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability
Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability
nvd
CVE-2024-21309P3HIGHCVSS 7.8fixed in 10.0.20348.2227≥ 10.0.20348.0, < 10.0.20348.22272024-01-09
CVE-2024-21309 [HIGH] CWE-191 CVE-2024-21309: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-21358P3HIGHCVSS 7.8fixed in 10.0.20348.3207≥ 10.0.20348.0, < 10.0.20348.32072025-02-11
CVE-2025-21358 [HIGH] CWE-822 CVE-2025-21358: Windows Core Messaging Elevation of Privileges Vulnerability
Windows Core Messaging Elevation of Privileges Vulnerability
nvd
CVE-2024-43626P3HIGHCVSS 7.8fixed in 10.0.20348.2849≥ 10.0.20348.0, < 10.0.20348.28492024-11-12
CVE-2024-43626 [HIGH] CWE-122 CVE-2024-43626: Windows Telephony Service Elevation of Privilege Vulnerability
Windows Telephony Service Elevation of Privilege Vulnerability
nvd
CVE-2024-43556P3HIGHCVSS 7.8fixed in 10.0.20348.2762≥ 10.0.20348.0, < 10.0.20348.27622024-10-08
CVE-2024-43556 [HIGH] CWE-416 CVE-2024-43556: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2024-38050P3HIGHCVSS 7.8fixed in 10.0.20348.2582≥ 10.0.20348.0, < 10.0.20348.25822024-07-09
CVE-2024-38050 [HIGH] CWE-191 CVE-2024-38050: Windows Workstation Service Elevation of Privilege Vulnerability
Windows Workstation Service Elevation of Privilege Vulnerability
nvd
CVE-2024-30049P3HIGHCVSS 7.8fixed in 10.0.20348.2461≥ 10.0.20348.0, < 10.0.20348.24612024-05-14
CVE-2024-30049 [HIGH] CWE-416 CVE-2024-30049: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2024-38079P3HIGHCVSS 7.8fixed in 10.0.20348.2582≥ 10.0.20348.0, < 10.0.20348.25822024-07-09
CVE-2024-38079 [HIGH] CWE-122 CVE-2024-38079: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2024-38250P3HIGHCVSS 7.8fixed in 10.0.20348.2700≥ 10.0.20348.0, < 10.0.20348.27002024-09-10
CVE-2024-38250 [HIGH] CWE-126 CVE-2024-38250: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2024-38247P3HIGHCVSS 7.8fixed in 10.0.20348.2700≥ 10.0.20348.0, < 10.0.20348.27002024-09-10
CVE-2024-38247 [HIGH] CWE-415 CVE-2024-38247: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2023-35355P3HIGHCVSS 7.8fixed in 10.0.20348.1970≥ 10.0.20348.0, < 10.0.20348.19702023-09-12
CVE-2023-35355 [HIGH] CWE-121 CVE-2023-35355: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-29994P3HIGHCVSS 7.8fixed in 10.0.20348.2461≥ 10.0.20348.0, < 10.0.20348.24612024-05-14
CVE-2024-29994 [HIGH] CWE-125 CVE-2024-29994: Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability
Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability
nvd
CVE-2025-49689P3HIGHCVSS 7.8fixed in 10.0.20348.3932≥ 10.0.20348.0, < 10.0.20348.39322025-07-08
CVE-2025-49689 [HIGH] CWE-125 CVE-2025-49689: Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevat
Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2022-37978P3HIGHCVSS 7.5≥ 10.0.20348.0, < 10.0.20348.11292022-10-11
CVE-2022-37978 [HIGH] CVE-2022-37978: Windows Active Directory Certificate Services Security Feature Bypass
Windows Active Directory Certificate Services Security Feature Bypass
nvd
CVE-2024-43509P3HIGHCVSS 7.8fixed in 10.0.20348.2762≥ 10.0.20348.0, < 10.0.20348.27622024-10-08
CVE-2024-43509 [HIGH] CWE-416 CVE-2024-43509: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2025-21367P3HIGHCVSS 7.8fixed in 10.0.20348.3207≥ 10.0.20348.0, < 10.0.20348.32072025-02-11
CVE-2025-21367 [HIGH] CWE-416 CVE-2025-21367: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2023-38141P3HIGHCVSS 7.8fixed in 10.0.20348.1970≥ 10.0.20348.0, < 10.0.20348.19702023-09-12
CVE-2023-38141 [HIGH] CWE-367 CVE-2023-38141: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd