cbcvebase.

Microsoft Windows Server 2022 23H2 vulnerabilities

1,556 known vulnerabilities affecting microsoft/windows_server_2022_23h2.

Total CVEs
1,556
CISA KEV
52
actively exploited
Public exploits
39
Exploited in wild
63
Severity breakdown
CRITICAL25HIGH1099MEDIUM426LOW6

Vulnerabilities

Page 54 of 78
CVE-2024-30050P3MEDIUMCVSS 5.4fixed in 10.0.25398.8872024-05-14
CVE-2024-30050 [MEDIUM] CWE-693 CVE-2024-30050: Windows Mark of the Web Security Feature Bypass Vulnerability Windows Mark of the Web Security Feature Bypass Vulnerability
nvd
CVE-2025-26651P3MEDIUMCVSS 6.5fixed in 10.0.25398.15512025-04-08
CVE-2025-26651 [MEDIUM] CWE-749 CVE-2025-26651: Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized att Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
nvd
CVE-2025-47978P3MEDIUMCVSS 6.5fixed in 10.0.25398.17322025-07-08
CVE-2025-47978 [MEDIUM] CWE-125 CVE-2025-47978: Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network. Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.
nvd
CVE-2025-59282P3HIGHCVSS 7.0fixed in 10.0.25398.19132025-10-14
CVE-2025-59282 [HIGH] CWE-362 CVE-2025-59282: Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-53147P3HIGHCVSS 7.0fixed in 10.0.25398.17912025-08-12
CVE-2025-53147 [HIGH] CWE-416 CVE-2025-53147: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55680P3HIGHCVSS 7.0fixed in 10.0.25398.19132025-10-14
CVE-2025-55680 [HIGH] CWE-367 CVE-2025-55680: Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows a Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-26672P3MEDIUMCVSS 6.5fixed in 10.0.25398.15512025-04-08
CVE-2025-26672 [MEDIUM] CWE-126 CVE-2025-26672: Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-26664P3MEDIUMCVSS 6.5fixed in 10.0.25398.15512025-04-08
CVE-2025-26664 [MEDIUM] CWE-126 CVE-2025-26664: Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-54115P3HIGHCVSS 7.0fixed in 10.0.25398.18492025-09-09
CVE-2025-54115 [HIGH] CWE-362 CVE-2025-54115: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53137P3HIGHCVSS 7.0fixed in 10.0.25398.17912025-08-12
CVE-2025-53137 [HIGH] CWE-416 CVE-2025-53137: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50167P3HIGHCVSS 7.0fixed in 10.0.25398.17912025-08-12
CVE-2025-50167 [HIGH] CWE-362 CVE-2025-50167: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53718P3HIGHCVSS 7.0fixed in 10.0.25398.17912025-08-12
CVE-2025-53718 [HIGH] CWE-416 CVE-2025-53718: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53721P3HIGHCVSS 7.0fixed in 10.0.25398.17912025-08-12
CVE-2025-53721 [HIGH] CWE-416 CVE-2025-53721: Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevat Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53142P3HIGHCVSS 7.0fixed in 10.0.25398.17912025-08-12
CVE-2025-53142 [HIGH] CWE-416 CVE-2025-53142: Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privilege Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53802P3HIGHCVSS 7.0fixed in 10.0.25398.18492025-09-09
CVE-2025-53802 [HIGH] CWE-416 CVE-2025-53802: Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges loca Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54112P3HIGHCVSS 7.0fixed in 10.0.25398.18492025-09-09
CVE-2025-54112 [HIGH] CWE-416 CVE-2025-54112: Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges l Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-58737P3HIGHCVSS 7.0fixed in 10.0.25398.19132025-10-14
CVE-2025-58737 [HIGH] CWE-416 CVE-2025-58737: Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally. Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-60717P3HIGHCVSS 7.0fixed in 10.0.25398.19652025-11-11
CVE-2025-60717 [HIGH] CWE-416 CVE-2025-60717: Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privil Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59515P3HIGHCVSS 7.0fixed in 10.0.25398.19652025-11-11
CVE-2025-59515 [HIGH] CWE-416 CVE-2025-59515: Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privil Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20831P3HIGHCVSS 7.0fixed in 10.0.25398.20922026-01-13
CVE-2026-20831 [HIGH] CWE-367 CVE-2026-20831: Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock a Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows Server 2022 23H2 vulnerabilities | cvebase