Known vulnerabilities in Windows Server 2022 20H2 - page 2

Vendor: Microsoft
Version: 2022 20H2
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 943
Public exploits: 37
Known exploited (KEV): 41
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Windows Server version 2022 20H2 Windows Server 2022 20H2 is affected by 943 vulnerabilities: 21 critical, 185 high, 267 medium, 470 low Critical High Medium Low

Vulnerabilities (943)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU117161 - Heap-based Buffer Overflow
CVE-2025-55697
CWE-122 Low
No
No
2012 R2 6.3.9600.22824, 2022 23H2 10.0.25398.1913, 2025 10.0.26100.6899 15.10.2025 SB2025101515
#VU117158 - Improper Validation of Specified Type of Input
CVE-2025-59257
CWE-1287 Medium
No
No
2012 R2 6.3.9600.22824, 2022 23H2 10.0.25398.1913, 2025 10.0.26100.6899 15.10.2025 SB2025101512
#VU117152 - Information Exposure Through Log Files
CVE-2025-47979
CWE-532 Low
No
No
2012 R2 6.3.9600.22824, 2022 23H2 10.0.25398.1913, 2025 10.0.26100.6899 15.10.2025 SB2025101509
#VU117150 - Use After Free
CVE-2025-48004
CWE-416 Low
No
No
2012 R2 6.3.9600.22774, 2022 23H2 10.0.25398.1913, 2025 10.0.26100.6899 15.10.2025 SB2025101508
#VU117145 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-58727
CWE-362 Low
No
No
2012 R2 6.3.9600.22824, 2022 23H2 10.0.25398.1913, 2025 10.0.26100.6899 15.10.2025 SB2025101506
#VU117106 - Improper Enforcement of Behavioral Workflow
CVE-2025-55330
CWE-841 Low
No
No
2012 R2 6.3.9600.22824, 2022 23H2 10.0.25398.1913, 2025 10.0.26100.6899 14.10.2025 SB2025101495
#VU117095 - Improper Access Control
CVE-2025-55694
CWE-284 Low
No
No
2012 R2 6.3.9600.22824, 2022 23H2 10.0.25398.1913, 2025 10.0.26100.6899 14.10.2025 SB2025101491
#VU117068 - Use After Free
CVE-2025-58728
CWE-416 Low
No
No
2012 R2 6.3.9600.22824, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2025 10.0.26100.6899 14.10.2025 SB2025101478
#VU117032 - Use After Free
CVE-2025-53150
CWE-416 Low
No
No
2012 R2 6.3.9600.22824, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2025 10.0.26100.6899 14.10.2025 SB2025101468
#VU117028 - Use of Uninitialized Resource
CVE-2025-59194
CWE-908 Low
No
No
2012 R2 6.3.9600.22824, 2022 23H2 10.0.25398.1913, 2025 10.0.26100.6899 14.10.2025 SB2025101466
#VU115092 - Use After Free
CVE-2025-54103
CWE-416 Low
No
No
2012 R2 6.3.9600.22774, 2022 23H2 10.0.25398.1849, 2025 10.0.26100.6508, 2025 10.0.26100.6584 09.09.2025 SB2025090997
#VU115091 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-54105
CWE-362 Low
No
No
2012 R2 6.3.9600.22774, 2022 23H2 10.0.25398.1849, 2025 10.0.26100.6508, 2025 10.0.26100.6584 09.09.2025 SB2025090996
#VU114009 - Exposure of sensitive information to an unauthorized actor
CVE-2025-53156
CWE-200 Low
No
No
2012 R2 6.3.9600.22725, 2022 23H2 10.0.25398.1791, 2025 10.0.26100.4851, 2025 10.0.26100.4946 13.08.2025 SB2025081357
#VU113986 - Use After Free
CVE-2025-53142
CWE-416 Low
No
No
2012 R2 6.3.9600.22725, 2022 23H2 10.0.25398.1791, 2025 10.0.26100.4851, 2025 10.0.26100.4946 13.08.2025 SB2025081323
#VU113900 - Type confusion
CVE-2025-50168
CWE-843 Low
Public exploit available
No
2012 R2 6.3.9600.22725, 2022 23H2 10.0.25398.1791, 2025 10.0.26100.4851, 2025 10.0.26100.4946 12.08.2025 SB2025081275
#VU112588 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-48799
CWE-59 Low
Public exploit available
No
2022 23H2 10.0.22621.5472, 2025 10.0.26100.4652 09.07.2025 SB2025070929
#VU112585 - Processor optimization removal or modification of security-critical code
CVE-2025-48809
CWE-1037 Low
No
No
2022 23H2 10.0.22621.5472, 2025 10.0.26100.4652 09.07.2025 SB2025070924
#VU112584 - Processor optimization removal or modification of security-critical code
CVE-2025-48810
CWE-1037 Low
No
No
2022 23H2 10.0.22621.5472, 2025 10.0.26100.4652 09.07.2025 SB2025070924
#VU112582 - Improper Access Control
CVE-2025-47993
CWE-284 Low
No
No
2022 23H2 10.0.25398.1732, 2025 10.0.26100.4652, 2025 10.0.26200.4349 09.07.2025 SB2025070922
#VU111030 - Out-of-bounds read
CVE-2025-2884
CWE-125 Low
No
No
2012 R2 6.3.9600.22824, 2022 23H2 10.0.25398.1913, 2025 10.0.26100.6899 11.06.2025 SB2025061103
SB2025061303
SB2025072845
and 3 more


Showing elements 21 - 40 out of 943