← Back to Products

windows_server_2022_23h2

Vendor: microsoft

1,004
Total CVEs
13
Critical
693
High
179
Medium
119
Low

Recent CVEs

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

8.1

CVSS

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

8.0

CVSS

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

9.8

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.0

CVSS

Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.8

CVSS

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.0

CVSS

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.0

CVSS

Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.8

CVSS

Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.5

CVSS

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

8.8

CVSS

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

5.5

CVSS

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

5.5

CVSS

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

5.5

CVSS

Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

5.5

CVSS

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

5.5

CVSS

Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an unauthorized attacker to execute code locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.8

CVSS

Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

5.5

CVSS

Use after free in Windows User Interface Core allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.8

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.8

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.8

CVSS

Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

8.4

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.8

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.8

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.8

CVSS

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.8

CVSS

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

6.5

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.0

CVSS

Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.3

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.0

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.0

CVSS

Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

5.5

CVSS

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

5.5

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.0

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.0

CVSS

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

5.5

CVSS

Use after free in Windows WalletService allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.0

CVSS

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

5.5

CVSS

Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.8

CVSS

Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.8

CVSS

Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.8

CVSS

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.0

CVSS

Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.8

CVSS

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.0

CVSS

Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

6.2

CVSS

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.5

CVSS

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.0

CVSS

Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.8

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

7.0

CVSS

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

5.5

CVSS

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally....

Affected versions: 10.0.25398.1009 10.0.25398.1085 10.0.25398.1128 10.0.25398.1189 10.0.25398.1251 +25 more

Published: Apr 14, 2026

5.5

CVSS