Microsoft Windows Server Version 20H2 vulnerabilities

966 known vulnerabilities affecting microsoft/windows_server_version_20h2.

Total CVEs
966
CISA KEV
39
actively exploited
Public exploits
8
Exploited in wild
44
Severity breakdown
CRITICAL44HIGH690MEDIUM229LOW3

Vulnerabilities

Page 7 of 49
CVE-2022-30164HIGHCVSS 7.8≥ 10.0.0, < 10.0.19042.17662022-06-15
CVE-2022-30164 [HIGH] CVE-2022-30164: Kerberos AppContainer Security Feature Bypass Vulnerability Kerberos AppContainer Security Feature Bypass Vulnerability
cvelistv5nvd
CVE-2022-30162MEDIUMCVSS 5.5≥ 10.0.0, < 10.0.19042.17662022-06-15
CVE-2022-30162 [MEDIUM] CVE-2022-30162: Windows Kernel Information Disclosure Vulnerability Windows Kernel Information Disclosure Vulnerability
cvelistv5nvd
CVE-2022-30155MEDIUMCVSS 5.5≥ 10.0.0, < 10.0.19042.17662022-06-15
CVE-2022-30155 [MEDIUM] Windows Kernel Denial of Service Vulnerability Windows Kernel Denial of Service Vulnerability Windows Kernel Denial of Service Vulnerability
cvelistv5
CVE-2022-30154MEDIUMCVSS 5.3≥ 10.0.0, < 10.0.19042.17662022-06-15
CVE-2022-30154 [MEDIUM] CVE-2022-30154: Microsoft File Server Shadow Copy Agent Service (RVSS) Elevation of Privilege Vulnerability Microsoft File Server Shadow Copy Agent Service (RVSS) Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2022-30148MEDIUMCVSS 5.5≥ 10.0.0, < 10.0.19042.17662022-06-15
CVE-2022-30148 [MEDIUM] CWE-532 CVE-2022-30148: Windows Desired State Configuration (DSC) Information Disclosure Vulnerability Windows Desired State Configuration (DSC) Information Disclosure Vulnerability
cvelistv5nvd
CVE-2022-32230HIGHCVSS 7.5≥ 19042.1706, < 19042.1706≥ 19043.1706, < 19043.1706+1 more2022-06-14
CVE-2022-32230 [HIGH] CWE-476 CVE-2022-32230: Microsoft Windows SMBv3 suffers from a null pointer dereference in versions of Windows prior to the Microsoft Windows SMBv3 suffers from a null pointer dereference in versions of Windows prior to the April, 2022 patch set. By sending a malformed FileNormalizedNameInformation SMBv3 request over a named pipe, an attacker can cause a Blue Screen of Death (BSOD) crash of the Windows kernel. For most systems, this attack requires authentication, except in
cvelistv5nvd
CVE-2022-30190HIGHCVSS 7.8KEV≥ 10.0.0, < 10.0.19042.17662022-06-01
CVE-2022-30190 [HIGH] CVE-2022-30190: A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calli A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the cont
cvelistv5nvd
CVE-2022-30138HIGHCVSS 7.8≥ 10.0.0, < 10.0.19042.17062022-05-18
CVE-2022-30138 [HIGH] CVE-2022-30138: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2022-22012CRITICALCVSS 9.8≥ 10.0.0, < 10.0.19042.17062022-05-10
CVE-2022-22012 [CRITICAL] CVE-2022-22012: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2022-29130CRITICALCVSS 9.8≥ 10.0.0, < 10.0.19042.17062022-05-10
CVE-2022-29130 [CRITICAL] CVE-2022-29130: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2022-26937CRITICALCVSS 9.8≥ 10.0.0, < 10.0.19042.17062022-05-10
CVE-2022-26937 [CRITICAL] CVE-2022-26937: Windows Network File System Remote Code Execution Vulnerability Windows Network File System Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2022-29125HIGHCVSS 7.0≥ 10.0.0, < 10.0.19042.17062022-05-10
CVE-2022-29125 [HIGH] CVE-2022-29125: Windows Push Notifications Apps Elevation of Privilege Vulnerability Windows Push Notifications Apps Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2022-26923HIGHCVSS 8.8KEV≥ 10.0.0, < 10.0.19042.17062022-05-10
CVE-2022-26923 [HIGH] CWE-295 CVE-2022-26923: Active Directory Domain Services Elevation of Privilege Vulnerability Active Directory Domain Services Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2022-29137HIGHCVSS 8.8≥ 10.0.0, < 10.0.19042.17062022-05-10
CVE-2022-29137 [HIGH] CVE-2022-29137: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2022-22016HIGHCVSS 7.0≥ 10.0.0, < 10.0.19042.17062022-05-10
CVE-2022-22016 [HIGH] CVE-2022-22016: Windows PlayToManager Elevation of Privilege Vulnerability Windows PlayToManager Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2022-22013HIGHCVSS 8.8≥ 10.0.0, < 10.0.19042.17062022-05-10
CVE-2022-22013 [HIGH] CVE-2022-22013: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2022-29129HIGHCVSS 8.8≥ 10.0.0, < 10.0.19042.17062022-05-10
CVE-2022-29129 [HIGH] CVE-2022-29129: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2022-29103HIGHCVSS 7.8≥ 10.0.0, < 10.0.19042.17062022-05-10
CVE-2022-29103 [HIGH] CVE-2022-29103: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2022-26926HIGHCVSS 7.8≥ 10.0.0, < 10.0.19042.17062022-05-10
CVE-2022-26926 [HIGH] CVE-2022-26926: Windows Address Book Remote Code Execution Vulnerability Windows Address Book Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2022-23270HIGHCVSS 8.1≥ 10.0.0, < 10.0.19042.17062022-05-10
CVE-2022-23270 [HIGH] CVE-2022-23270: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
cvelistv5nvd