cbcvebase.

Microsoft Windows Server 2022 23H2 vulnerabilities

1,556 known vulnerabilities affecting microsoft/windows_server_2022_23h2.

Total CVEs
1,556
CISA KEV
52
actively exploited
Public exploits
39
Exploited in wild
63
Severity breakdown
CRITICAL25HIGH1099MEDIUM426LOW6

Vulnerabilities

Page 48 of 78
CVE-2026-20876P3MEDIUMCVSS 6.7fixed in 10.0.25398.20922026-01-13
CVE-2026-20876 [MEDIUM] CWE-122 CVE-2026-20876: Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authoriz Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-64670P3MEDIUMCVSS 6.5fixed in 10.0.25398.20252025-12-09
CVE-2025-64670 [MEDIUM] CWE-200 CVE-2025-64670: Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over a network.
nvd
CVE-2025-29809P3HIGHCVSS 7.1fixed in 10.0.25398.15512025-04-08
CVE-2025-29809 [HIGH] CWE-922 CVE-2025-29809: Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypas Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2024-21438P3HIGHCVSS 7.5fixed in 10.0.25398.8302024-03-12
CVE-2024-21438 [HIGH] CWE-369 CVE-2024-21438: Microsoft AllJoyn API Denial of Service Vulnerability Microsoft AllJoyn API Denial of Service Vulnerability
nvd
CVE-2024-38031P3HIGHCVSS 7.5fixed in 10.0.25398.10092024-07-09
CVE-2024-38031 [HIGH] CWE-400 CVE-2024-38031: Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
nvd
CVE-2024-38068P3HIGHCVSS 7.5fixed in 10.0.25398.10092024-07-09
CVE-2024-38068 [HIGH] CWE-400 CVE-2024-38068: Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
nvd
CVE-2024-38067P3HIGHCVSS 7.5fixed in 10.0.25398.10092024-07-09
CVE-2024-38067 [HIGH] CWE-400 CVE-2024-38067: Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
nvd
CVE-2025-21351P3HIGHCVSS 7.5fixed in 10.0.25398.14252025-02-11
CVE-2025-21351 [HIGH] CWE-400 CVE-2025-21351: Windows Active Directory Domain Services API Denial of Service Vulnerability Windows Active Directory Domain Services API Denial of Service Vulnerability
nvd
CVE-2024-49121P3HIGHCVSS 7.5fixed in 10.0.25398.13082024-12-12
CVE-2024-49121 [HIGH] CWE-476 CVE-2024-49121: Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
nvd
CVE-2024-43541P3HIGHCVSS 7.5fixed in 10.0.25398.11892024-10-08
CVE-2024-43541 [HIGH] CWE-400 CVE-2024-43541: Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability
nvd
CVE-2024-43515P3HIGHCVSS 7.5fixed in 10.0.25398.11892024-10-08
CVE-2024-43515 [HIGH] CWE-400 CVE-2024-43515: Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability
nvd
CVE-2024-43545P3HIGHCVSS 7.5fixed in 10.0.25398.11892024-10-08
CVE-2024-43545 [HIGH] CWE-400 CVE-2024-43545: Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
nvd
CVE-2024-43544P3HIGHCVSS 7.5fixed in 10.0.25398.11892024-10-08
CVE-2024-43544 [HIGH] CWE-400 CVE-2024-43544: Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability
nvd
CVE-2024-21443P3HIGHCVSS 7.3fixed in 10.0.25398.7632024-03-12
CVE-2024-21443 [HIGH] CWE-416 CVE-2024-21443: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-26216P3HIGHCVSS 7.3fixed in 10.0.25398.8302024-04-09
CVE-2024-26216 [HIGH] CWE-59 CVE-2024-26216: Windows File Server Resource Management Service Elevation of Privilege Vulnerability Windows File Server Resource Management Service Elevation of Privilege Vulnerability
nvd
CVE-2024-43615P3HIGHCVSS 7.1fixed in 10.0.25398.11892024-10-08
CVE-2024-43615 [HIGH] CWE-73 CVE-2024-43615: Microsoft OpenSSH for Windows Remote Code Execution Vulnerability Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
nvd
CVE-2025-49680P3HIGHCVSS 7.3fixed in 10.0.25398.17322025-07-08
CVE-2025-49680 [HIGH] CWE-59 CVE-2025-49680: Improper link resolution before file access ('link following') in Windows Performance Recorder allow Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized attacker to deny service locally.
nvd
CVE-2026-32093P3HIGHCVSS 7.0fixed in 10.0.25398.22742026-04-14
CVE-2026-32093 [HIGH] CWE-122 CVE-2026-32093: Concurrent execution using shared resource with improper synchronization ('race condition') in Funct Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-26233P3MEDIUMCVSS 6.6fixed in 10.0.25398.8302024-04-09
CVE-2024-26233 [MEDIUM] CWE-416 CVE-2024-26233: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2024-26224P3MEDIUMCVSS 6.6fixed in 10.0.25398.8302024-04-09
CVE-2024-26224 [MEDIUM] CWE-416 CVE-2024-26224: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2022 23H2 vulnerabilities | cvebase