Msrc Windows Server 2022 23H2 Edition vulnerabilities
1,038 known vulnerabilities affecting msrc/windows_server_2022_23h2_edition.
Total CVEs
1,038
CISA KEV
33
actively exploited
Public exploits
14
Exploited in wild
16
Severity breakdown
CRITICAL12HIGH696MEDIUM326LOW4
Vulnerabilities
Page 37 of 52
CVE-2024-43543MEDIUMCVSS 6.82024-10-08
CVE-2024-43543 [MEDIUM] CWE-601 Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the Attack Vector is Physical (AV:P). What does that mean for this vulnerability?
An attacker needs physical access to the target computer to plug in a malicious USB drive.
Windows Mobile Broadband: Windows Mobile Broadband
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Co
msrc
CVE-2024-43540MEDIUMCVSS 6.52024-10-08
CVE-2024-43540 [MEDIUM] CWE-20 Windows Mobile Broadband Driver Denial of Service Vulnerability
Windows Mobile Broadband Driver Denial of Service Vulnerability
FAQ: According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability?
Exploiting this vulnerability requires an attacker to be within proximity of the target system to send and receive radio transmissions.
Windows Mobile Broadband: Windows Mobile Broadband
Microsoft: Microsoft
Customer Act
msrc
CVE-2024-43554MEDIUMCVSS 5.52024-10-08
CVE-2024-43554 [MEDIUM] CWE-212 Windows Kernel-Mode Driver Information Disclosure Vulnerability
Windows Kernel-Mode Driver Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is memory layout - the vulnerability allows an attacker to collect information that facilitates predicting addressing of the memory.
Windows Kernel-Mode Drivers:
msrc
CVE-2024-43537MEDIUMCVSS 6.52024-10-08
CVE-2024-43537 [MEDIUM] CWE-908 Windows Mobile Broadband Driver Denial of Service Vulnerability
Windows Mobile Broadband Driver Denial of Service Vulnerability
FAQ: According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability?
Exploiting this vulnerability requires an attacker to be within proximity of the target system to send and receive radio transmissions.
Windows Mobile Broadband: Windows Mobile Broadband
Microsoft: Microsoft
Customer Ac
msrc
CVE-2024-37983MEDIUMCVSS 6.72024-10-08
CVE-2024-37983 [MEDIUM] CWE-822 Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could bypass Secure Boot.
Windows EFI Partition: Windows EFI Partition
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Security
msrc
CVE-2024-43526MEDIUMCVSS 6.82024-10-08
CVE-2024-43526 [MEDIUM] CWE-20 Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the Attack Vector is Physical (AV:P). What does that mean for this vulnerability?
An attacker needs physical access to the target computer to plug in a malicious USB drive.
Windows Mobile Broadband: Windows Mobile Broadband
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Cod
msrc
CVE-2024-43561MEDIUMCVSS 6.52024-10-08
CVE-2024-43561 [MEDIUM] CWE-20 Windows Mobile Broadband Driver Denial of Service Vulnerability
Windows Mobile Broadband Driver Denial of Service Vulnerability
FAQ: According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability?
Exploiting this vulnerability requires an attacker to be within proximity of the target system to send and receive radio transmissions.
Windows Mobile Broadband: Windows Mobile Broadband
Microsoft: Microsoft
Customer Act
msrc
CVE-2024-38240HIGHCVSS 8.12024-09-10
CVE-2024-38240 [HIGH] CWE-125 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
FAQ: Windows 11, version 24H2 is not generally available yet. Why are there updates for this version of Windows listed in the Security Updates table?
The new Copilot+ devices that are now publicly available come with Windows 11, version 24H2 installed. Customers with these devices need to know about any vulnerab
msrc
CVE-2024-38238HIGHCVSS 7.82024-09-10
CVE-2024-38238 [HIGH] CWE-122 Kernel Streaming Service Driver Elevation of Privilege Vulnerability
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
FAQ: Windows 11, version 24H2 is not generally available yet. Why are there updates for this version of Windows listed in the Security Updates table?
The new Copilot+ devices that are now publicly available come with Windows 11, version 24H2 installed. Customers with these devices need to know about any vulnerabilities that affec
msrc
CVE-2024-43455HIGHCVSS 8.82024-09-10
CVE-2024-43455 [HIGH] CWE-20 Windows Remote Desktop Licensing Service Spoofing Vulnerability
Windows Remote Desktop Licensing Service Spoofing Vulnerability
FAQ: How could an attacker exploit this vulnerability?
To successfully exploit this vulnerability an attacker must send specially crafted requests to the Terminal Server Licensing Service, which must be running and accessible over the network.
Windows Remote Desktop Licensing Service: Windows Remote Desktop Licensing Service
Microsoft: Mi
msrc
CVE-2024-38263HIGHCVSS 7.52024-09-10
CVE-2024-38263 [HIGH] CWE-591 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does
msrc
CVE-2024-38244HIGHCVSS 7.82024-09-10
CVE-2024-38244 [HIGH] CWE-20 Kernel Streaming Service Driver Elevation of Privilege Vulnerability
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
FAQ: Windows 11, version 24H2 is not generally available yet. Why are there updates for this version of Windows listed in the Security Updates table?
The new Copilot+ devices that are now publicly available come with Windows 11, version 24H2 installed. Customers with these devices need to know about any vulnerabilities that affect
msrc
CVE-2024-38119HIGHCVSS 7.52024-09-10
CVE-2024-38119 [HIGH] CWE-416 Windows Network Address Translation (NAT) Remote Code Execution Vulnerability
Windows Network Address Translation (NAT) Remote Code Execution Vulnerability
FAQ: Windows 11, version 24H2 is not generally available yet. Why are there updates for this version of Windows listed in the Security Updates table?
The new Copilot+ devices that are now publicly available come with Windows 11, version 24H2 installed. Customers with these devices need to know about any vulnerab
msrc
CVE-2024-38243HIGHCVSS 7.82024-09-10
CVE-2024-38243 [HIGH] CWE-20 Kernel Streaming Service Driver Elevation of Privilege Vulnerability
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
FAQ: Windows 11, version 24H2 is not generally available yet. Why are there updates for this version of Windows listed in the Security Updates table?
The new Copilot+ devices that are now publicly available come with Windows 11, version 24H2 installed. Customers with these devices need to know about any vulnerabilities that affect
msrc
CVE-2024-38046HIGHCVSS 7.82024-09-10
CVE-2024-38046 [HIGH] CWE-20 PowerShell Elevation of Privilege Vulnerability
PowerShell Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could elevate their user privileges from those of a restrained user to an unrestrained WDAC user.
FAQ: Windows 11, version 24H2 is not generally available yet. Why are there updates for this version of Windows listed
msrc
CVE-2024-21416HIGHCVSS 8.12024-09-10
CVE-2024-21416 [HIGH] CWE-122 Windows TCP/IP Remote Code Execution Vulnerability
Windows TCP/IP Remote Code Execution Vulnerability
FAQ: Windows 11, version 24H2 is not generally available yet. Why are there updates for this version of Windows listed in the Security Updates table?
The new Copilot+ devices that are now publicly available come with Windows 11, version 24H2 installed. Customers with these devices need to know about any vulnerabilities that affect their machine and to install the u
msrc
CVE-2024-38241HIGHCVSS 7.82024-09-10
CVE-2024-38241 [HIGH] CWE-20 Kernel Streaming Service Driver Elevation of Privilege Vulnerability
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
FAQ: Windows 11, version 24H2 is not generally available yet. Why are there updates for this version of Windows listed in the Security Updates table?
The new Copilot+ devices that are now publicly available come with Windows 11, version 24H2 installed. Customers with these devices need to know about any vulnerabilities that affect
msrc
CVE-2024-38248HIGHCVSS 7.02024-09-10
CVE-2024-38248 [HIGH] CWE-416 Windows Storage Elevation of Privilege Vulnerability
Windows Storage Elevation of Privilege Vulnerability
FAQ: Windows 11, version 24H2 is not generally available yet. Why are there updates for this version of Windows listed in the Security Updates table?
The new Copilot+ devices that are now publicly available come with Windows 11, version 24H2 installed. Customers with these devices need to know about any vulnerabilities that affect their machine and to install t
msrc
CVE-2024-43467HIGHCVSS 7.52024-09-10
CVE-2024-43467 [HIGH] CWE-362 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condition.
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulner
msrc
CVE-2024-38242HIGHCVSS 7.82024-09-10
CVE-2024-38242 [HIGH] CWE-122 Kernel Streaming Service Driver Elevation of Privilege Vulnerability
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
FAQ: Windows 11, version 24H2 is not generally available yet. Why are there updates for this version of Windows listed in the Security Updates table?
The new Copilot+ devices that are now publicly available come with Windows 11, version 24H2 installed. Customers with these devices need to know about any vulnerabilities that affec
msrc