Microsoft Windows Server 2022 23H2 vulnerabilities
1,556 known vulnerabilities affecting microsoft/windows_server_2022_23h2.
Total CVEs
1,556
CISA KEV
52
actively exploited
Public exploits
39
Exploited in wild
63
Severity breakdown
CRITICAL25HIGH1099MEDIUM426LOW6
Vulnerabilities
Page 33 of 78
CVE-2025-24073P3HIGHCVSS 7.8fixed in 10.0.25398.15512025-04-08
CVE-2025-24073 [HIGH] CWE-20 CVE-2025-24073: Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privi
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-29811P3HIGHCVSS 7.8fixed in 10.0.25398.15512025-04-08
CVE-2025-29811 [HIGH] CWE-20 CVE-2025-29811: Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privi
Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-60709P3HIGHCVSS 7.8fixed in 10.0.25398.19652025-11-11
CVE-2025-60709 [HIGH] CWE-125 CVE-2025-60709: Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate
Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24046P3HIGHCVSS 7.8fixed in 10.0.25398.14862025-03-11
CVE-2025-24046 [HIGH] CWE-416 CVE-2025-24046: Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges lo
Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-24293P3HIGHCVSS 7.8fixed in 10.0.25398.22072026-03-10
CVE-2026-24293 [HIGH] CWE-476 CVE-2026-24293: Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attac
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20832P3HIGHCVSS 7.8fixed in 10.0.25398.20922026-01-13
CVE-2026-20832 [HIGH] CWE-415 CVE-2026-20832: Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerabili
Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability
nvd
CVE-2026-20857P3HIGHCVSS 7.8fixed in 10.0.25398.20922026-01-13
CVE-2026-20857 [HIGH] CWE-822 CVE-2026-20857: Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacke
Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-32712P3HIGHCVSS 7.8fixed in 10.0.25398.16652025-06-10
CVE-2025-32712 [HIGH] CWE-416 CVE-2025-32712: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53726P3HIGHCVSS 7.8fixed in 10.0.25398.17912025-08-12
CVE-2025-53726 [HIGH] CWE-843 CVE-2025-53726: Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows a
Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53724P3HIGHCVSS 7.8fixed in 10.0.25398.17912025-08-12
CVE-2025-53724 [HIGH] CWE-843 CVE-2025-53724: Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows a
Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50155P3HIGHCVSS 7.8fixed in 10.0.25398.17912025-08-12
CVE-2025-50155 [HIGH] CWE-122 CVE-2025-50155: Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows a
Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53725P3HIGHCVSS 7.8fixed in 10.0.25398.17912025-08-12
CVE-2025-53725 [HIGH] CWE-843 CVE-2025-53725: Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows a
Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54102P3HIGHCVSS 7.8fixed in 10.0.25398.18492025-09-09
CVE-2025-54102 [HIGH] CWE-416 CVE-2025-54102: Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevat
Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-33838P3HIGHCVSS 7.8fixed in 10.0.25398.23302026-05-12
CVE-2026-33838 [HIGH] CWE-415 CVE-2026-33838: Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50152P3HIGHCVSS 7.8fixed in 10.0.25398.19132025-10-14
CVE-2025-50152 [HIGH] CWE-125 CVE-2025-50152: Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55339P3HIGHCVSS 7.8fixed in 10.0.25398.19132025-10-14
CVE-2025-55339 [HIGH] CWE-125 CVE-2025-55339: Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50170P3HIGHCVSS 7.8fixed in 10.0.25398.17912025-08-12
CVE-2025-50170 [HIGH] CWE-280 CVE-2025-50170: Improper handling of insufficient permissions or privileges in Windows Cloud Files Mini Filter Drive
Improper handling of insufficient permissions or privileges in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59505P3HIGHCVSS 7.8fixed in 10.0.25398.19652025-11-11
CVE-2025-59505 [HIGH] CWE-415 CVE-2025-59505: Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally.
Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-60713P3HIGHCVSS 7.8fixed in 10.0.25398.19652025-11-11
CVE-2025-60713 [HIGH] CWE-822 CVE-2025-60713: Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authoriz
Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20822P3HIGHCVSS 7.8fixed in 10.0.25398.20922026-01-13
CVE-2026-20822 [HIGH] CWE-416 CVE-2026-20822: Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges l
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd