Microsoft Windows Server 2022 23H2 vulnerabilities
1,556 known vulnerabilities affecting microsoft/windows_server_2022_23h2.
Total CVEs
1,556
CISA KEV
52
actively exploited
Public exploits
39
Exploited in wild
64
Severity breakdown
CRITICAL25HIGH1099MEDIUM426LOW6
Vulnerabilities
Page 70 of 78
CVE-2026-20838P4MEDIUMCVSS 5.5fixed in 10.0.25398.20922026-01-13
CVE-2026-20838 [MEDIUM] CWE-209 CVE-2026-20838: Generation of error message containing sensitive information in Windows Kernel allows an authorized
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2025-53804P4MEDIUMCVSS 5.5fixed in 10.0.25398.18492025-09-09
CVE-2025-53804 [MEDIUM] CWE-200 CVE-2025-53804: Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized at
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2025-59186P4MEDIUMCVSS 5.5fixed in 10.0.25398.19132025-10-14
CVE-2025-59186 [MEDIUM] CWE-200 CVE-2025-59186: Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized at
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2026-21222P4MEDIUMCVSS 5.5fixed in 10.0.25398.21492026-02-10
CVE-2026-21222 [MEDIUM] CWE-532 CVE-2026-21222: Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2025-47979P4MEDIUMCVSS 5.5fixed in 10.0.25398.19132025-10-14
CVE-2025-47979 [MEDIUM] CWE-532 CVE-2025-47979: Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized at
Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally.
nvd
CVE-2025-55683P4MEDIUMCVSS 5.5fixed in 10.0.25398.19132025-10-14
CVE-2025-55683 [MEDIUM] CWE-200 CVE-2025-55683: Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized at
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2025-29837P4MEDIUMCVSS 5.5fixed in 10.0.25398.16112025-05-13
CVE-2025-29837 [MEDIUM] CWE-59 CVE-2025-29837: Improper link resolution before file access ('link following') in Windows Installer allows an author
Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally.
nvd
CVE-2025-55699P4MEDIUMCVSS 5.5fixed in 10.0.25398.19132025-10-14
CVE-2025-55699 [MEDIUM] CWE-200 CVE-2025-55699: Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized at
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2025-59510P4MEDIUMCVSS 5.5fixed in 10.0.25398.19652025-11-11
CVE-2025-59510 [MEDIUM] CWE-59 CVE-2025-59510: Improper link resolution before file access ('link following') in Windows Routing and Remote Access
Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service locally.
nvd
CVE-2025-24068P4MEDIUMCVSS 5.5fixed in 10.0.25398.16652025-06-10
CVE-2025-24068 [MEDIUM] CWE-126 CVE-2025-24068: Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose in
Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2026-20939P4MEDIUMCVSS 5.5fixed in 10.0.25398.20922026-01-13
CVE-2026-20939 [MEDIUM] CWE-200 CVE-2026-20939: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-20937P4MEDIUMCVSS 5.5fixed in 10.0.25398.20922026-01-13
CVE-2026-20937 [MEDIUM] CWE-200 CVE-2026-20937: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2025-60706P4MEDIUMCVSS 5.5fixed in 10.0.25398.19652025-11-11
CVE-2025-60706 [MEDIUM] CWE-125 CVE-2025-60706: Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32085P4MEDIUMCVSS 5.5fixed in 10.0.25398.22742026-04-14
CVE-2026-32085 [MEDIUM] CWE-200 CVE-2026-32085: Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows a
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information locally.
nvd
CVE-2025-21340P4MEDIUMCVSS 5.5fixed in 10.0.25398.13692025-01-14
CVE-2025-21340 [MEDIUM] CWE-284 CVE-2025-21340: Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability
Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability
nvd
CVE-2025-59209P4MEDIUMCVSS 5.5fixed in 10.0.25398.19132025-10-14
CVE-2025-59209 [MEDIUM] CWE-200 CVE-2025-59209: Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
nvd
CVE-2025-49684P4MEDIUMCVSS 5.5fixed in 10.0.25398.17322025-07-08
CVE-2025-49684 [MEDIUM] CWE-126 CVE-2025-49684: Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locall
Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2024-21362P4MEDIUMCVSS 5.5fixed in 10.0.25398.7092024-02-13
CVE-2024-21362 [MEDIUM] CWE-367 CVE-2024-21362: Windows Kernel Security Feature Bypass Vulnerability
Windows Kernel Security Feature Bypass Vulnerability
nvd
CVE-2026-32081P4MEDIUMCVSS 5.5fixed in 10.0.25398.22742026-04-14
CVE-2026-32081 [MEDIUM] CWE-200 CVE-2026-32081: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2025-59188P4MEDIUMCVSS 5.5fixed in 10.0.25398.19132025-10-14
CVE-2025-59188 [MEDIUM] CWE-200 CVE-2025-59188: Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an aut
Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to disclose information locally.
nvd