cbcvebase.

Microsoft Windows Server 2022 23H2 vulnerabilities

1,556 known vulnerabilities affecting microsoft/windows_server_2022_23h2.

Total CVEs
1,556
CISA KEV
52
actively exploited
Public exploits
39
Exploited in wild
63
Severity breakdown
CRITICAL25HIGH1099MEDIUM426LOW6

Vulnerabilities

Page 7 of 78
CVE-2024-49080P2HIGHCVSS 8.8fixed in 10.0.25398.13082024-12-12
CVE-2024-49080 [HIGH] CWE-122 CVE-2024-49080: Windows IP Routing Management Snapin Remote Code Execution Vulnerability Windows IP Routing Management Snapin Remote Code Execution Vulnerability
nvd
CVE-2025-21376P3HIGHCVSS 8.1fixed in 10.0.25398.14252025-02-11
CVE-2025-21376 [HIGH] CWE-122 CVE-2025-21376: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2026-20868P2HIGHCVSS 8.8fixed in 10.0.25398.20922026-01-13
CVE-2026-20868 [HIGH] CWE-122 CVE-2026-20868: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-62456P2HIGHCVSS 8.8fixed in 10.0.25398.20252025-12-09
CVE-2025-62456 [HIGH] CWE-122 CVE-2025-62456: Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network.
nvd
CVE-2026-23669P2HIGHCVSS 8.8fixed in 10.0.25398.22072026-03-10
CVE-2026-23669 [HIGH] CWE-416 CVE-2026-23669: Use after free in RPC Runtime allows an authorized attacker to execute code over a network. Use after free in RPC Runtime allows an authorized attacker to execute code over a network.
nvd
CVE-2024-43454P3HIGHCVSS 7.1fixed in 10.0.25398.11282024-09-10
CVE-2024-43454 [HIGH] CWE-23 CVE-2024-43454: Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
nvd
CVE-2025-49708P3CRITICALCVSS 9.9fixed in 10.0.25398.19132025-10-14
CVE-2025-49708 [CRITICAL] CWE-416 CVE-2025-49708: Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges o Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2024-30010P2HIGHCVSS 8.8fixed in 10.0.25398.8872024-05-14
CVE-2024-30010 [HIGH] CWE-23 CVE-2024-30010: Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2025-27480P3HIGHCVSS 8.1fixed in 10.0.25398.15512025-04-08
CVE-2025-27480 [HIGH] CWE-416 CVE-2025-27480: Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code ove Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-43593P2HIGHCVSS 8.8fixed in 10.0.25398.11892024-10-08
CVE-2024-43593 [HIGH] CWE-20 CVE-2024-43593: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-43592P2HIGHCVSS 8.8fixed in 10.0.25398.11892024-10-08
CVE-2024-43592 [HIGH] CWE-20 CVE-2024-43592: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-38260P2HIGHCVSS 8.8fixed in 10.0.25398.11282024-09-10
CVE-2024-38260 [HIGH] CWE-908 CVE-2024-38260: Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
nvd
CVE-2025-64678P2HIGHCVSS 8.8fixed in 10.0.25398.19652025-12-09
CVE-2025-64678 [HIGH] CWE-122 CVE-2025-64678: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-43452P3HIGHCVSS 7.5fixed in 10.0.25398.12512024-11-12
CVE-2024-43452 [HIGH] CWE-367 CVE-2024-43452: Windows Registry Elevation of Privilege Vulnerability Windows Registry Elevation of Privilege Vulnerability
nvd
CVE-2025-26647P2HIGHCVSS 8.8fixed in 10.0.25398.15512025-04-08
CVE-2025-26647 [HIGH] CWE-20 CVE-2025-26647: Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges ov Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2025-50171P2CRITICALCVSS 9.1fixed in 10.0.25398.17912025-08-12
CVE-2025-50171 [CRITICAL] CWE-862 CVE-2025-50171: Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing o Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2024-30078P3HIGHCVSS 8.8fixed in 10.0.25398.9502024-06-11
CVE-2024-30078 [HIGH] CWE-20 CVE-2024-30078: Windows Wi-Fi Driver Remote Code Execution Vulnerability Windows Wi-Fi Driver Remote Code Execution Vulnerability
nvd
CVE-2025-33070P3HIGHCVSS 8.1fixed in 10.0.25398.16652025-06-10
CVE-2025-33070 [HIGH] CWE-908 CVE-2025-33070: Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privile Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2024-38240P3CRITICALCVSS 9.8fixed in 10.0.25398.11282024-09-10
CVE-2024-38240 [CRITICAL] CWE-125 CVE-2024-38240: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
nvd
CVE-2025-26645P3HIGHCVSS 8.8fixed in 10.0.25398.14862025-03-11
CVE-2025-26645 [HIGH] CWE-23 CVE-2025-26645: Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code ove Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
Microsoft Windows Server 2022 23H2 vulnerabilities | cvebase