Microsoft Windows Server 2022 23H2 vulnerabilities

1,380 known vulnerabilities affecting microsoft/windows_server_2022_23h2.

Total CVEs
1,380
CISA KEV
51
actively exploited
Public exploits
23
Exploited in wild
19
Severity breakdown
CRITICAL22HIGH958MEDIUM394LOW6

Vulnerabilities

Page 68 of 69
CVE-2024-21359HIGHCVSS 8.8fixed in 10.0.25398.7092024-02-13
CVE-2024-21359 [HIGH] CWE-122 CVE-2024-21359: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21348HIGHCVSS 7.5fixed in 10.0.25398.7092024-02-13
CVE-2024-21348 [HIGH] CWE-122 CVE-2024-21348: Internet Connection Sharing (ICS) Denial of Service Vulnerability Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd
CVE-2024-21349HIGHCVSS 8.8fixed in 10.0.25398.7092024-02-13
CVE-2024-21349 [HIGH] CWE-122 CVE-2024-21349: Microsoft ActiveX Data Objects Remote Code Execution Vulnerability Microsoft ActiveX Data Objects Remote Code Execution Vulnerability
nvd
CVE-2024-21371HIGHCVSS 7.0fixed in 10.0.25398.7092024-02-13
CVE-2024-21371 [HIGH] CWE-367 CVE-2024-21371: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-21356MEDIUMCVSS 6.5fixed in 10.0.25398.7092024-02-13
CVE-2024-21356 [MEDIUM] CWE-476 CVE-2024-21356: Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
nvd
CVE-2024-21340MEDIUMCVSS 4.6≤ 10.0.25398.7092024-02-13
CVE-2024-21340 [MEDIUM] CWE-126 CVE-2024-21340: Windows Kernel Information Disclosure Vulnerability Windows Kernel Information Disclosure Vulnerability
nvd
CVE-2024-21339MEDIUMCVSS 6.4fixed in 10.0.25398.7092024-02-13
CVE-2024-21339 [MEDIUM] CWE-416 CVE-2024-21339: Windows USB Generic Parent Driver Remote Code Execution Vulnerability Windows USB Generic Parent Driver Remote Code Execution Vulnerability
nvd
CVE-2024-21362MEDIUMCVSS 5.5fixed in 10.0.25398.7092024-02-13
CVE-2024-21362 [MEDIUM] CWE-367 CVE-2024-21362: Windows Kernel Security Feature Bypass Vulnerability Windows Kernel Security Feature Bypass Vulnerability
nvd
CVE-2024-21341MEDIUMCVSS 6.8≤ 10.0.25398.7092024-02-13
CVE-2024-21341 [MEDIUM] CWE-122 CVE-2024-21341: Windows Kernel Remote Code Execution Vulnerability Windows Kernel Remote Code Execution Vulnerability
nvd
CVE-2024-21344MEDIUMCVSS 5.9fixed in 10.0.25398.7092024-02-13
CVE-2024-21344 [MEDIUM] CWE-125 CVE-2024-21344: Windows Network Address Translation (NAT) Denial of Service Vulnerability Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2024-21310HIGHCVSS 7.8fixed in 10.0.25398.6432024-01-09
CVE-2024-21310 [HIGH] CWE-197 CVE-2024-21310: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-20700HIGHCVSS 7.5fixed in 10.0.25398.6432024-01-09
CVE-2024-20700 [HIGH] CWE-362 CVE-2024-20700: Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2024-20698HIGHCVSS 7.8fixed in 10.0.25398.6432024-01-09
CVE-2024-20698 [HIGH] CWE-190 CVE-2024-20698: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-20696HIGHCVSS 7.3fixed in 10.0.25398.6432024-01-09
CVE-2024-20696 [HIGH] CWE-122 CVE-2024-20696: Windows libarchive Remote Code Execution Vulnerability Windows libarchive Remote Code Execution Vulnerability
nvd
CVE-2024-21309HIGHCVSS 7.8fixed in 10.0.25398.6432024-01-09
CVE-2024-21309 [HIGH] CWE-191 CVE-2024-21309: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-21314MEDIUMCVSS 6.5fixed in 10.0.25398.6432024-01-09
CVE-2024-21314 [MEDIUM] CWE-125 CVE-2024-21314: Microsoft Message Queuing Information Disclosure Vulnerability Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2024-21316MEDIUMCVSS 6.1fixed in 10.0.25398.6432024-01-09
CVE-2024-21316 [MEDIUM] CWE-20 CVE-2024-21316: Windows Server Key Distribution Service Security Feature Bypass Windows Server Key Distribution Service Security Feature Bypass
nvd
CVE-2024-20692MEDIUMCVSS 5.7fixed in 10.0.25398.6432024-01-09
CVE-2024-20692 [MEDIUM] CWE-326 CVE-2024-20692: Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
nvd
CVE-2024-21305MEDIUMCVSS 4.4fixed in 10.0.25398.6432024-01-09
CVE-2024-21305 [MEDIUM] CWE-732 CVE-2024-21305: Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
nvd
CVE-2024-20694MEDIUMCVSS 5.5fixed in 10.0.25398.6432024-01-09
CVE-2024-20694 [MEDIUM] CWE-908 CVE-2024-20694: Windows CoreMessaging Information Disclosure Vulnerability Windows CoreMessaging Information Disclosure Vulnerability
nvd