Msrc Windows Server 2022 23H2 Edition vulnerabilities

1,038 known vulnerabilities affecting msrc/windows_server_2022_23h2_edition.

Total CVEs
1,038
CISA KEV
33
actively exploited
Public exploits
14
Exploited in wild
16
Severity breakdown
CRITICAL12HIGH696MEDIUM326LOW4

Vulnerabilities

Page 40 of 52
CVE-2024-38138HIGHCVSS 7.52024-08-13
CVE-2024-38138 [HIGH] CWE-416 Windows Deployment Services Remote Code Execution Vulnerability Windows Deployment Services Remote Code Execution Vulnerability FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? For an attacker to exploit this vulnerability, they would need to have knowledge of a specific operation that triggers a memory allocation failure, specifically a use after free. FAQ: According to the CVSS metric, privilege
msrc
CVE-2024-38145HIGHCVSS 7.52024-08-13
CVE-2024-38145 [HIGH] CWE-476 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability FAQ: Windows 11, version 24H2 is not generally available yet. Why are there updates for this version of Windows listed in the Security Updates table? The new Copilot+ devices that are now publicly available come with Windows 11, version 24H2 installed. Customers with these devices need to know about any vulnerabilities that aff
msrc
CVE-2024-38128HIGHCVSS 8.82024-08-13
CVE-2024-38128 [HIGH] CWE-190 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability FAQ: According to the CVSS metric, the attack vector is network (AV:N) and the user interaction is required (UI:R). What is the target context of the remote code execution? This attack requires an admin user on the client to connect to a malicious server, and that could allow the attacker to gain c
msrc
CVE-2024-38135HIGHCVSS 7.82024-08-13
CVE-2024-38135 [HIGH] CWE-126 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. FAQ: Windows 11, version 24H2 is not generally available yet. Why are there updates for this version of Windows listed in the Securit
msrc
CVE-2024-37968HIGHCVSS 7.52024-08-13
CVE-2024-37968 [HIGH] CWE-345 Windows DNS Spoofing Vulnerability Windows DNS Spoofing Vulnerability Microsoft Windows DNS: Microsoft Windows DNS Microsoft: Microsoft Customer Action Required: Yes Impact: Spoofing Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5041578 Reference: https://support.microsoft.com/help/5041578 Reference: https://catalog.update.microsoft.c
msrc
CVE-2024-38214MEDIUMCVSS 6.52024-08-13
CVE-2024-38214 [MEDIUM] CWE-125 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to major loss of confidentiality (C:H) but have no effect on integrity (I:N) or on availability (A:N). What does that mean for this vulnerability? An attacker who successfully exploited the vulnerabilit
msrc
CVE-2024-21302MEDIUMCVSS 6.72024-08-13
CVE-2024-21302 [MEDIUM] CWE-284 Windows Secure Kernel Mode Elevation of Privilege Vulnerability Windows Secure Kernel Mode Elevation of Privilege Vulnerability Description: Summary: As of July 10, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtualization-based security related updates and the Recommended Actions section of this CVE for guidance on how to protect your systems from this vulnerability. An elevation of pr
msrc
CVE-2024-38223MEDIUMCVSS 6.82024-08-13
CVE-2024-38223 [MEDIUM] CWE-284 Windows Initial Machine Configuration Elevation of Privilege Vulnerability Windows Initial Machine Configuration Elevation of Privilege Vulnerability FAQ: According to the CVSS metric, the attack vector is physical (AV:P). What does that mean for this vulnerability? To exploit this vulnerability, an attacker needs physical access to the victim's machine. FAQ: How could an attacker exploit this vulnerability? An unauthenticated attacker can use a specially crafte
msrc
CVE-2024-38213MEDIUMCVSS 6.5KEV2024-08-13
CVE-2024-38213 [MEDIUM] CWE-693 Windows Mark of the Web Security Feature Bypass Vulnerability Windows Mark of the Web Security Feature Bypass Vulnerability FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability? An attacker who successfully exploited this vulnerability could bypass the SmartScreen user experience. FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? An attacker must send
msrc
CVE-2024-38143MEDIUMCVSS 4.22024-08-13
CVE-2024-38143 [MEDIUM] CWE-306 Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability FAQ: How could an attacker exploit this vulnerability? An unauthenticated attacker could exploit the vulnerability by interacting with a malicious wireless network from the lock screen of a device. Successful exploitation of this vulnerability does not crash systems or allow unauthorized access. However, it can potentially leak
msrc
CVE-2024-38077CRITICALCVSS 9.82024-07-09
CVE-2024-38077 [CRITICAL] CWE-122 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability FAQ: How would an attacker exploit this vulnerability? An unauthenticated attacker could connect to the Remote Desktop Licensing Service and send a malicious message which could allow remote code execution. Windows Remote Desktop Licensing Service: Windows Remote Desktop Licensing Service Microsoft: Microsof
msrc
CVE-2024-38074CRITICALCVSS 9.82024-07-09
CVE-2024-38074 [CRITICAL] CWE-191 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability FAQ: How could an attacker exploit this vulnerability? An attacker could send a specially crafted packet to a server set up as a Remote Desktop Licensing server, which will cause remote code execution. Windows Remote Desktop Licensing Service: Windows Remote Desktop Licensing Service Microsoft: Microsoft Cu
msrc
CVE-2024-38076CRITICALCVSS 9.82024-07-09
CVE-2024-38076 [CRITICAL] CWE-122 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability FAQ: How could an attacker exploit this vulnerability? An attacker could send a specially crafted packet to a server set up as a Remote Desktop Licensing server, which will cause remote code execution. Windows Remote Desktop: Windows Remote Desktop Microsoft: Microsoft Customer Action Required: Yes Impact:
msrc
CVE-2024-38069HIGHCVSS 7.02024-07-09
CVE-2024-38069 [HIGH] CWE-347 Windows Enroll Engine Security Feature Bypass Vulnerability Windows Enroll Engine Security Feature Bypass Vulnerability FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to gather information specific to the environment and take additional actions prior to exploitation to prepare the target environment. FAQ: What kind of security fe
msrc
CVE-2024-37977HIGHCVSS 8.02024-07-09
CVE-2024-37977 [HIGH] CWE-122 Secure Boot Security Feature Bypass Vulnerability Secure Boot Security Feature Bypass Vulnerability FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability? An attacker who successfully exploited this vulnerability could bypass Secure Boot. FAQ: According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability? An unauthenticated attacker with LAN access could exploit this vuln
msrc
CVE-2024-38034HIGHCVSS 7.82024-07-09
CVE-2024-38034 [HIGH] CWE-190 Windows Filtering Platform Elevation of Privilege Vulnerability Windows Filtering Platform Elevation of Privilege Vulnerability FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability? An attacker who successfully exploited this vulnerability could gain administrator privileges. Windows Filtering: Windows Filtering Microsoft: Microsoft Customer Action Required: Yes Impact: Elevation of Privilege Exploit Status: Publicly
msrc
CVE-2024-38073HIGHCVSS 7.52024-07-09
CVE-2024-38073 [HIGH] CWE-125 Windows Remote Desktop Licensing Service Denial of Service Vulnerability Windows Remote Desktop Licensing Service Denial of Service Vulnerability FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to total loss of availability (A:H)? What does that mean for this vulnerability? An attacker could impact availability of the service resulting in Denial of Service (DoS). Windows Remote Desktop Licensing Service: Windows Remote D
msrc
CVE-2024-38053HIGHCVSS 8.82024-07-09
CVE-2024-38053 [HIGH] CWE-416 Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability FAQ: According to the CVSS score, the attack vector is adjacent (AV:A). What does this mean for this vulnerability? This attack is limited to systems connected to the same network segment as the attacker. The attack cannot be performed across multiple networks (for example, a WAN) and would be limited to systems on the
msrc
CVE-2024-37988HIGHCVSS 8.02024-07-09
CVE-2024-37988 [HIGH] CWE-130 Secure Boot Security Feature Bypass Vulnerability Secure Boot Security Feature Bypass Vulnerability FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability? An attacker who successfully exploited this vulnerability could bypass Secure Boot. FAQ: According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability? An unauthenticated attacker with LAN access could exploit this vuln
msrc
CVE-2024-38071HIGHCVSS 7.52024-07-09
CVE-2024-38071 [HIGH] CWE-126 Windows Remote Desktop Licensing Service Denial of Service Vulnerability Windows Remote Desktop Licensing Service Denial of Service Vulnerability FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to total loss of availability (A:H)? What does that mean for this vulnerability? An attacker could impact availability of the service resulting in Denial of Service (DoS). Windows Remote Desktop Licensing Service: Windows Remote D
msrc
Msrc Windows Server 2022 23H2 Edition vulnerabilities | cvebase