Microsoft Windows Server 2022 23H2 vulnerabilities
1,380 known vulnerabilities affecting microsoft/windows_server_2022_23h2.
Total CVEs
1,380
CISA KEV
51
actively exploited
Public exploits
23
Exploited in wild
19
Severity breakdown
CRITICAL22HIGH958MEDIUM394LOW6
Vulnerabilities
Page 38 of 69
CVE-2025-21420HIGHCVSS 7.8fixed in 10.0.25398.14252025-02-11
CVE-2025-21420 [HIGH] CWE-59 CVE-2025-21420: Windows Disk Cleanup Tool Elevation of Privilege Vulnerability
Windows Disk Cleanup Tool Elevation of Privilege Vulnerability
nvd
CVE-2025-21184HIGHCVSS 7.0fixed in 10.0.25398.14252025-02-11
CVE-2025-21184 [HIGH] CWE-122 CVE-2025-21184: Windows Core Messaging Elevation of Privileges Vulnerability
Windows Core Messaging Elevation of Privileges Vulnerability
nvd
CVE-2025-21201HIGHCVSS 8.8fixed in 10.0.25398.14252025-02-11
CVE-2025-21201 [HIGH] CWE-415 CVE-2025-21201: Windows Telephony Server Remote Code Execution Vulnerability
Windows Telephony Server Remote Code Execution Vulnerability
nvd
CVE-2025-21351HIGHCVSS 7.5fixed in 10.0.25398.14252025-02-11
CVE-2025-21351 [HIGH] CWE-400 CVE-2025-21351: Windows Active Directory Domain Services API Denial of Service Vulnerability
Windows Active Directory Domain Services API Denial of Service Vulnerability
nvd
CVE-2025-21200HIGHCVSS 8.8fixed in 10.0.25398.14252025-02-11
CVE-2025-21200 [HIGH] CWE-122 CVE-2025-21200: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21371HIGHCVSS 8.8fixed in 10.0.25398.14252025-02-11
CVE-2025-21371 [HIGH] CWE-122 CVE-2025-21371: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21347MEDIUMCVSS 6.0fixed in 10.0.25398.14252025-02-11
CVE-2025-21347 [MEDIUM] CWE-59 CVE-2025-21347: Windows Deployment Services Denial of Service Vulnerability
Windows Deployment Services Denial of Service Vulnerability
nvd
CVE-2025-21212MEDIUMCVSS 6.5fixed in 10.0.25398.14252025-02-11
CVE-2025-21212 [MEDIUM] CWE-125 CVE-2025-21212: Internet Connection Sharing (ICS) Denial of Service Vulnerability
Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd
CVE-2025-21216MEDIUMCVSS 6.5fixed in 10.0.25398.14252025-02-11
CVE-2025-21216 [MEDIUM] CWE-125 CVE-2025-21216: Internet Connection Sharing (ICS) Denial of Service Vulnerability
Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd
CVE-2025-21349MEDIUMCVSS 6.8fixed in 10.0.25398.14252025-02-11
CVE-2025-21349 [MEDIUM] CWE-287 CVE-2025-21349: Windows Remote Desktop Configuration Service Tampering Vulnerability
Windows Remote Desktop Configuration Service Tampering Vulnerability
nvd
CVE-2025-21254MEDIUMCVSS 6.5fixed in 10.0.25398.14252025-02-11
CVE-2025-21254 [MEDIUM] CWE-125 CVE-2025-21254: Internet Connection Sharing (ICS) Denial of Service Vulnerability
Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd
CVE-2025-21352MEDIUMCVSS 6.5fixed in 10.0.25398.14252025-02-11
CVE-2025-21352 [MEDIUM] CWE-400 CVE-2025-21352: Internet Connection Sharing (ICS) Denial of Service Vulnerability
Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd
CVE-2025-21311CRITICALCVSS 9.8fixed in 10.0.25398.13692025-01-14
CVE-2025-21311 [CRITICAL] CWE-303 CVE-2025-21311: Windows NTLM V1 Elevation of Privilege Vulnerability
Windows NTLM V1 Elevation of Privilege Vulnerability
nvd
CVE-2025-21307CRITICALCVSS 9.8fixed in 10.0.25398.13692025-01-14
CVE-2025-21307 [CRITICAL] CWE-416 CVE-2025-21307: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
nvd
CVE-2025-21291HIGHCVSS 8.8fixed in 10.0.25398.13692025-01-14
CVE-2025-21291 [HIGH] CWE-415 CVE-2025-21291: Windows Direct Show Remote Code Execution Vulnerability
Windows Direct Show Remote Code Execution Vulnerability
nvd
CVE-2025-21326HIGHCVSS 7.8fixed in 10.0.25398.13692025-01-14
CVE-2025-21326 [HIGH] CWE-843 CVE-2025-21326: Internet Explorer Remote Code Execution Vulnerability
Internet Explorer Remote Code Execution Vulnerability
nvd
CVE-2025-21239HIGHCVSS 8.8fixed in 10.0.25398.13692025-01-14
CVE-2025-21239 [HIGH] CWE-122 CVE-2025-21239: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21293HIGHCVSS 8.8PoCfixed in 10.0.25398.13692025-01-14
CVE-2025-21293 [HIGH] CWE-284 CVE-2025-21293: Active Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2025-21378HIGHCVSS 7.8fixed in 10.0.25398.13692025-01-14
CVE-2025-21378 [HIGH] CWE-122 CVE-2025-21378: Windows CSC Service Elevation of Privilege Vulnerability
Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2025-21300HIGHCVSS 7.5fixed in 10.0.25398.13692025-01-14
CVE-2025-21300 [HIGH] CWE-400 CVE-2025-21300: Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability
Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability
nvd