Microsoft Windows Server 2022 23H2 vulnerabilities

1,380 known vulnerabilities affecting microsoft/windows_server_2022_23h2.

Total CVEs
1,380
CISA KEV
51
actively exploited
Public exploits
23
Exploited in wild
19
Severity breakdown
CRITICAL22HIGH958MEDIUM394LOW6

Vulnerabilities

Page 69 of 69
CVE-2024-21313MEDIUMCVSS 5.3fixed in 10.0.25398.6432024-01-09
CVE-2024-21313 [MEDIUM] CWE-209 CVE-2024-21313: Windows TCP/IP Information Disclosure Vulnerability Windows TCP/IP Information Disclosure Vulnerability
nvd
CVE-2024-21311MEDIUMCVSS 5.5fixed in 10.0.25398.6432024-01-09
CVE-2024-21311 [MEDIUM] CWE-125 CVE-2024-21311: Windows Cryptographic Services Information Disclosure Vulnerability Windows Cryptographic Services Information Disclosure Vulnerability
nvd
CVE-2023-35628HIGHCVSS 8.1fixed in 10.0.25398.5842023-12-12
CVE-2023-35628 [HIGH] CWE-416 CVE-2023-35628: Windows MSHTML Platform Remote Code Execution Vulnerability Windows MSHTML Platform Remote Code Execution Vulnerability
nvd
CVE-2023-35630HIGHCVSS 8.8fixed in 10.0.25398.5842023-12-12
CVE-2023-35630 [HIGH] CWE-122 CVE-2023-35630: Internet Connection Sharing (ICS) Remote Code Execution Vulnerability Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
nvd
CVE-2023-36696HIGHCVSS 7.8fixed in 10.0.25398.5842023-12-12
CVE-2023-36696 [HIGH] CWE-125 CVE-2023-36696: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-24023MEDIUMCVSS 6.8fixed in 10.0.25398.5312023-11-28
CVE-2023-24023 [MEDIUM] CVE-2023-24023: Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow certain man-in-the-middle attacks that force a short key length, and might lead to discovery of the encryption key and live injection, aka BLUFFS.
nvd
CVE-2023-36407HIGHCVSS 7.8fixed in 10.0.25398.5312023-11-14
CVE-2023-36407 [HIGH] CWE-20 CVE-2023-36407: Windows Hyper-V Elevation of Privilege Vulnerability Windows Hyper-V Elevation of Privilege Vulnerability
nvd
CVE-2023-36405HIGHCVSS 7.0fixed in 10.0.25398.5312023-11-14
CVE-2023-36405 [HIGH] CWE-362 CVE-2023-36405: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-36705HIGHCVSS 7.8fixed in 10.0.25398.5312023-11-14
CVE-2023-36705 [HIGH] CWE-59 CVE-2023-36705: Windows Installer Elevation of Privilege Vulnerability Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2023-36427HIGHCVSS 7.0fixed in 10.0.25398.5312023-11-14
CVE-2023-36427 [HIGH] CVE-2023-36427: Windows Hyper-V Elevation of Privilege Vulnerability Windows Hyper-V Elevation of Privilege Vulnerability
nvd
CVE-2023-36719HIGHCVSS 7.8fixed in 10.0.25398.5312023-11-14
CVE-2023-36719 [HIGH] CWE-20 CVE-2023-36719: Microsoft Speech Application Programming Interface (SAPI) Elevation of Privilege Vulnerability Microsoft Speech Application Programming Interface (SAPI) Elevation of Privilege Vulnerability
nvd
CVE-2023-36403HIGHCVSS 7.0fixed in 10.0.25398.5312023-11-14
CVE-2023-36403 [HIGH] CWE-591 CVE-2023-36403: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-36033HIGHCVSS 7.8KEVfixed in 10.0.25398.5312023-11-14
CVE-2023-36033 [HIGH] CWE-822 CVE-2023-36033: Windows DWM Core Library Elevation of Privilege Vulnerability Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2023-36425HIGHCVSS 8.0fixed in 10.0.25398.5312023-11-14
CVE-2023-36425 [HIGH] CWE-122 CVE-2023-36425: Windows Distributed File System (DFS) Remote Code Execution Vulnerability Windows Distributed File System (DFS) Remote Code Execution Vulnerability
nvd
CVE-2023-36424HIGHCVSS 7.8KEVfixed in 10.0.25398.5312023-11-14
CVE-2023-36424 [HIGH] CWE-125 CVE-2023-36424: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-36408HIGHCVSS 7.8fixed in 10.0.25398.5312023-11-14
CVE-2023-36408 [HIGH] CWE-122 CVE-2023-36408: Windows Hyper-V Elevation of Privilege Vulnerability Windows Hyper-V Elevation of Privilege Vulnerability
nvd
CVE-2023-36406MEDIUMCVSS 5.5fixed in 10.0.25398.5312023-11-14
CVE-2023-36406 [MEDIUM] CWE-20 CVE-2023-36406: Windows Hyper-V Information Disclosure Vulnerability Windows Hyper-V Information Disclosure Vulnerability
nvd
CVE-2023-36404MEDIUMCVSS 5.5fixed in 10.0.25398.5312023-11-14
CVE-2023-36404 [MEDIUM] CWE-284 CVE-2023-36404: Windows Kernel Information Disclosure Vulnerability Windows Kernel Information Disclosure Vulnerability
nvd
CVE-2023-36428MEDIUMCVSS 5.5fixed in 10.0.25398.5312023-11-14
CVE-2023-36428 [MEDIUM] CWE-125 CVE-2023-36428: Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
nvd
CVE-2023-20588MEDIUMCVSS 5.5fixed in 10.0.25398.5842023-08-08
CVE-2023-20588 [MEDIUM] CWE-369 CVE-2023-20588: A division-by-zero error on some AMD processors can potentially return speculative data resulting i A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality.
nvd