Microsoft Windows Server 2022 23H2 vulnerabilities
1,556 known vulnerabilities affecting microsoft/windows_server_2022_23h2.
Total CVEs
1,556
CISA KEV
52
actively exploited
Public exploits
39
Exploited in wild
63
Severity breakdown
CRITICAL25HIGH1099MEDIUM426LOW6
Vulnerabilities
Page 48 of 78
CVE-2026-20876P3MEDIUMCVSS 6.7fixed in 10.0.25398.20922026-01-13
CVE-2026-20876 [MEDIUM] CWE-122 CVE-2026-20876: Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authoriz
Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-64670P3MEDIUMCVSS 6.5fixed in 10.0.25398.20252025-12-09
CVE-2025-64670 [MEDIUM] CWE-200 CVE-2025-64670: Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an
Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over a network.
nvd
CVE-2025-29809P3HIGHCVSS 7.1fixed in 10.0.25398.15512025-04-08
CVE-2025-29809 [HIGH] CWE-922 CVE-2025-29809: Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypas
Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2024-21438P3HIGHCVSS 7.5fixed in 10.0.25398.8302024-03-12
CVE-2024-21438 [HIGH] CWE-369 CVE-2024-21438: Microsoft AllJoyn API Denial of Service Vulnerability
Microsoft AllJoyn API Denial of Service Vulnerability
nvd
CVE-2024-38031P3HIGHCVSS 7.5fixed in 10.0.25398.10092024-07-09
CVE-2024-38031 [HIGH] CWE-400 CVE-2024-38031: Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
nvd
CVE-2024-38068P3HIGHCVSS 7.5fixed in 10.0.25398.10092024-07-09
CVE-2024-38068 [HIGH] CWE-400 CVE-2024-38068: Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
nvd
CVE-2024-38067P3HIGHCVSS 7.5fixed in 10.0.25398.10092024-07-09
CVE-2024-38067 [HIGH] CWE-400 CVE-2024-38067: Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
nvd
CVE-2025-21351P3HIGHCVSS 7.5fixed in 10.0.25398.14252025-02-11
CVE-2025-21351 [HIGH] CWE-400 CVE-2025-21351: Windows Active Directory Domain Services API Denial of Service Vulnerability
Windows Active Directory Domain Services API Denial of Service Vulnerability
nvd
CVE-2024-49121P3HIGHCVSS 7.5fixed in 10.0.25398.13082024-12-12
CVE-2024-49121 [HIGH] CWE-476 CVE-2024-49121: Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
nvd
CVE-2024-43541P3HIGHCVSS 7.5fixed in 10.0.25398.11892024-10-08
CVE-2024-43541 [HIGH] CWE-400 CVE-2024-43541: Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability
Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability
nvd
CVE-2024-43515P3HIGHCVSS 7.5fixed in 10.0.25398.11892024-10-08
CVE-2024-43515 [HIGH] CWE-400 CVE-2024-43515: Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability
Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability
nvd
CVE-2024-43545P3HIGHCVSS 7.5fixed in 10.0.25398.11892024-10-08
CVE-2024-43545 [HIGH] CWE-400 CVE-2024-43545: Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
nvd
CVE-2024-43544P3HIGHCVSS 7.5fixed in 10.0.25398.11892024-10-08
CVE-2024-43544 [HIGH] CWE-400 CVE-2024-43544: Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability
Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability
nvd
CVE-2024-21443P3HIGHCVSS 7.3fixed in 10.0.25398.7632024-03-12
CVE-2024-21443 [HIGH] CWE-416 CVE-2024-21443: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-26216P3HIGHCVSS 7.3fixed in 10.0.25398.8302024-04-09
CVE-2024-26216 [HIGH] CWE-59 CVE-2024-26216: Windows File Server Resource Management Service Elevation of Privilege Vulnerability
Windows File Server Resource Management Service Elevation of Privilege Vulnerability
nvd
CVE-2024-43615P3HIGHCVSS 7.1fixed in 10.0.25398.11892024-10-08
CVE-2024-43615 [HIGH] CWE-73 CVE-2024-43615: Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
nvd
CVE-2025-49680P3HIGHCVSS 7.3fixed in 10.0.25398.17322025-07-08
CVE-2025-49680 [HIGH] CWE-59 CVE-2025-49680: Improper link resolution before file access ('link following') in Windows Performance Recorder allow
Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized attacker to deny service locally.
nvd
CVE-2026-32093P3HIGHCVSS 7.0fixed in 10.0.25398.22742026-04-14
CVE-2026-32093 [HIGH] CWE-122 CVE-2026-32093: Concurrent execution using shared resource with improper synchronization ('race condition') in Funct
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-26233P3MEDIUMCVSS 6.6fixed in 10.0.25398.8302024-04-09
CVE-2024-26233 [MEDIUM] CWE-416 CVE-2024-26233: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2024-26224P3MEDIUMCVSS 6.6fixed in 10.0.25398.8302024-04-09
CVE-2024-26224 [MEDIUM] CWE-416 CVE-2024-26224: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd