Microsoft Windows Server 2022 23H2 vulnerabilities
1,556 known vulnerabilities affecting microsoft/windows_server_2022_23h2.
Total CVEs
1,556
CISA KEV
52
actively exploited
Public exploits
39
Exploited in wild
63
Severity breakdown
CRITICAL25HIGH1099MEDIUM426LOW6
Vulnerabilities
Page 31 of 78
CVE-2026-32078P3HIGHCVSS 7.8fixed in 10.0.25398.22742026-04-14
CVE-2026-32078 [HIGH] CWE-416 CVE-2026-32078: Use after free in Windows Projected File System allows an authorized attacker to elevate privileges
Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32074P3HIGHCVSS 7.8fixed in 10.0.25398.22742026-04-14
CVE-2026-32074 [HIGH] CWE-415 CVE-2026-32074: Double free in Windows Projected File System allows an authorized attacker to elevate privileges loc
Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32069P3HIGHCVSS 7.8fixed in 10.0.25398.22742026-04-14
CVE-2026-32069 [HIGH] CWE-415 CVE-2026-32069: Double free in Windows Projected File System allows an authorized attacker to elevate privileges loc
Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59278P3HIGHCVSS 7.8fixed in 10.0.25398.19132025-10-14
CVE-2025-59278 [HIGH] CWE-1287 CVE-2025-59278: Improper validation of specified type of input in Windows Authentication Methods allows an authorize
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59275P3HIGHCVSS 7.8fixed in 10.0.25398.19132025-10-14
CVE-2025-59275 [HIGH] CWE-122 CVE-2025-59275: Improper validation of specified type of input in Windows Authentication Methods allows an authorize
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32089P3HIGHCVSS 7.8fixed in 10.0.25398.22742026-04-14
CVE-2026-32089 [HIGH] CWE-362 CVE-2026-32089: Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges lo
Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59502P3HIGHCVSS 7.5fixed in 10.0.25398.18492025-10-14
CVE-2025-59502 [HIGH] CWE-400 CVE-2025-59502: Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker t
Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-27916P3HIGHCVSS 7.8fixed in 10.0.25398.22742026-04-14
CVE-2026-27916 [HIGH] CWE-416 CVE-2026-27916: Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker t
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-64661P3HIGHCVSS 7.8fixed in 10.0.25398.20252025-12-09
CVE-2025-64661 [HIGH] CWE-362 CVE-2025-64661: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-27923P3HIGHCVSS 7.8fixed in 10.0.25398.22742026-04-14
CVE-2026-27923 [HIGH] CWE-416 CVE-2026-27923: Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32160P3HIGHCVSS 7.8fixed in 10.0.25398.22742026-04-14
CVE-2026-32160 [HIGH] CWE-362 CVE-2026-32160: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32159P3HIGHCVSS 7.8fixed in 10.0.25398.22742026-04-14
CVE-2026-32159 [HIGH] CWE-362 CVE-2026-32159: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32158P3HIGHCVSS 7.8fixed in 10.0.25398.22742026-04-14
CVE-2026-32158 [HIGH] CWE-362 CVE-2026-32158: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20930P3HIGHCVSS 7.8fixed in 10.0.25398.22742026-04-14
CVE-2026-20930 [HIGH] CWE-362 CVE-2026-20930: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26168P3HIGHCVSS 7.8fixed in 10.0.25398.22742026-04-14
CVE-2026-26168 [HIGH] CWE-362 CVE-2026-26168: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26167P3HIGHCVSS 7.8fixed in 10.0.25398.22742026-04-14
CVE-2026-26167 [HIGH] CWE-362 CVE-2026-26167: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-29831P3HIGHCVSS 7.5fixed in 10.0.25398.16112025-05-13
CVE-2025-29831 [HIGH] CWE-416 CVE-2025-29831: Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code ove
Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-27913P3HIGHCVSS 7.7fixed in 10.0.25398.22742026-04-14
CVE-2026-27913 [HIGH] CWE-20 CVE-2026-27913: Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security
Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security feature locally.
nvd
CVE-2026-20844P3HIGHCVSS 7.4fixed in 10.0.25398.20922026-01-13
CVE-2026-20844 [HIGH] CWE-362 CVE-2026-20844: Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges loc
Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-32156P3HIGHCVSS 7.4fixed in 10.0.25398.22742026-04-14
CVE-2026-32156 [HIGH] CWE-416 CVE-2026-32156: Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to execute code locally.
nvd