Microsoft Windows Server 2022 23H2 vulnerabilities

1,380 known vulnerabilities affecting microsoft/windows_server_2022_23h2.

Total CVEs
1,380
CISA KEV
51
actively exploited
Public exploits
23
Exploited in wild
19
Severity breakdown
CRITICAL22HIGH958MEDIUM394LOW6

Vulnerabilities

Page 56 of 69
CVE-2024-38146HIGHCVSS 7.5fixed in 10.0.25398.10852024-08-13
CVE-2024-38146 [HIGH] CWE-476 CVE-2024-38146: Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
nvd
CVE-2024-38193HIGHCVSS 7.8KEVPoCfixed in 10.0.25398.10852024-08-13
CVE-2024-38193 [HIGH] CWE-416 CVE-2024-38193: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd
CVE-2024-38138HIGHCVSS 7.5fixed in 10.0.25398.10852024-08-13
CVE-2024-38138 [HIGH] CWE-416 CVE-2024-38138: Windows Deployment Services Remote Code Execution Vulnerability Windows Deployment Services Remote Code Execution Vulnerability
nvd
CVE-2024-38153HIGHCVSS 7.8fixed in 10.0.25398.10852024-08-13
CVE-2024-38153 [HIGH] CWE-367 CVE-2024-38153: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-38118MEDIUMCVSS 5.5fixed in 10.0.25398.10852024-08-13
CVE-2024-38118 [MEDIUM] CWE-908 CVE-2024-38118: Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
nvd
CVE-2024-38213MEDIUMCVSS 6.5KEVfixed in 10.0.25398.9502024-08-13
CVE-2024-38213 [MEDIUM] CWE-693 CVE-2024-38213: Windows Mark of the Web Security Feature Bypass Vulnerability Windows Mark of the Web Security Feature Bypass Vulnerability
nvd
CVE-2024-38214MEDIUMCVSS 6.5fixed in 10.0.25398.10852024-08-13
CVE-2024-38214 [MEDIUM] CWE-125 CVE-2024-38214: Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
nvd
CVE-2024-38122MEDIUMCVSS 5.5fixed in 10.0.25398.10852024-08-13
CVE-2024-38122 [MEDIUM] CWE-908 CVE-2024-38122: Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
nvd
CVE-2024-38223MEDIUMCVSS 6.8fixed in 10.0.25398.10852024-08-13
CVE-2024-38223 [MEDIUM] CWE-284 CVE-2024-38223: Windows Initial Machine Configuration Elevation of Privilege Vulnerability Windows Initial Machine Configuration Elevation of Privilege Vulnerability
nvd
CVE-2024-38143MEDIUMCVSS 4.2fixed in 10.0.25398.10852024-08-13
CVE-2024-38143 [MEDIUM] CWE-306 CVE-2024-38143: Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability
nvd
CVE-2024-38151MEDIUMCVSS 5.5fixed in 10.0.25398.10852024-08-13
CVE-2024-38151 [MEDIUM] CWE-125 CVE-2024-38151: Windows Kernel Information Disclosure Vulnerability Windows Kernel Information Disclosure Vulnerability
nvd
CVE-2024-21302MEDIUMCVSS 6.7fixed in 10.0.25398.10852024-08-08
CVE-2024-21302 [MEDIUM] CWE-284 CVE-2024-21302: Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See K Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtualization-based security related updates and the Recommended Actions section of this CVE for guidance on how to protect your systems from this vulnerability. An elevation of privilege vulnerability exis
nvd
CVE-2024-21417HIGHCVSS 8.8fixed in 10.0.25398.10092024-07-10
CVE-2024-21417 [HIGH] CWE-862 CVE-2024-21417: Windows Text Services Framework Elevation of Privilege Vulnerability Windows Text Services Framework Elevation of Privilege Vulnerability
nvd
CVE-2024-38074CRITICALCVSS 9.8fixed in 10.0.25398.10092024-07-09
CVE-2024-38074 [CRITICAL] CWE-191 CVE-2024-38074: Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
nvd
CVE-2024-38076CRITICALCVSS 9.8fixed in 10.0.25398.10092024-07-09
CVE-2024-38076 [CRITICAL] CWE-122 CVE-2024-38076: Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
nvd
CVE-2024-38077CRITICALCVSS 9.8fixed in 10.0.25398.10092024-07-09
CVE-2024-38077 [CRITICAL] CWE-122 CVE-2024-38077: Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
nvd
CVE-2024-38022HIGHCVSS 7.0fixed in 10.0.25398.10092024-07-09
CVE-2024-38022 [HIGH] CWE-59 CVE-2024-38022: Windows Image Acquisition Elevation of Privilege Vulnerability Windows Image Acquisition Elevation of Privilege Vulnerability
nvd
CVE-2024-38052HIGHCVSS 7.8fixed in 10.0.25398.10092024-07-09
CVE-2024-38052 [HIGH] CWE-20 CVE-2024-38052: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-38064HIGHCVSS 7.5fixed in 10.0.25398.10092024-07-09
CVE-2024-38064 [HIGH] CWE-908 CVE-2024-38064: Windows TCP/IP Information Disclosure Vulnerability Windows TCP/IP Information Disclosure Vulnerability
nvd
CVE-2024-38079HIGHCVSS 7.8fixed in 10.0.25398.10092024-07-09
CVE-2024-38079 [HIGH] CWE-122 CVE-2024-38079: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd