Microsoft Vulnerabilities and Affected Products
Vulnerabilities associated with Windows Server version 20H2.
Products
Clear product- Windows Server 20194,131 vulnerabilities
- Windows Server 2019 (Server Core installation)4,034 vulnerabilities
- Windows 10 Version 18093,762 vulnerabilities
- Windows Server 20163,677 vulnerabilities
- Windows Server 20223,485 vulnerabilities
- Windows Server 2016 (Server Core installation)3,473 vulnerabilities
- Windows 10 Version 16073,184 vulnerabilities
- Windows 10 Version 21H23,063 vulnerabilities
- Windows Server 2012 R22,998 vulnerabilities
- Windows Server 2012 R2 (Server Core installation)2,853 vulnerabilities
- Windows Server 20122,824 vulnerabilities
- Windows Server 2012 (Server Core installation)2,691 vulnerabilities
- Windows 10 Version 22H22,565 vulnerabilities
- Windows 10 Version 15072,277 vulnerabilities
- Windows 11 Version 24H21,924 vulnerabilities
- Windows Server 20251,917 vulnerabilities
- Windows Server 2025 (Server Core installation)1,917 vulnerabilities
- Windows Server 2008 R2 Service Pack 11,874 vulnerabilities
- Windows Server 2008 R2 Service Pack 1 (Server Core installation)1,860 vulnerabilities
- Windows 11 Version 23H21,845 vulnerabilities
- Windows 11 version 22H21,776 vulnerabilities
- Windows Server 2022, 23H2 Edition (Server Core installation)1,725 vulnerabilities
- Windows Server 2008 Service Pack 2 (Server Core installation)1,667 vulnerabilities
- Windows Server 2008 Service Pack 21,664 vulnerabilities
- Windows 11 version 21H21,560 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-35759MEDIUM | Windows Local Security Authority (LSA) Denial of Service VulnerabilityWindows Local Security Authority (LSA) Denial of Service Vulnerability May 31, 2023 | CVSS6.5v3.1 | EPSS1.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35758MEDIUM | Windows Kernel Memory Information Disclosure VulnerabilityWindows Kernel Memory Information Disclosure Vulnerability May 31, 2023 | CVSS5.5v3.1 | EPSS0.497% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35757HIGH | Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityWindows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability May 31, 2023 | CVSS7.3v3.1 | EPSS0.776% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35756HIGH | Windows Kerberos Elevation of Privilege VulnerabilityWindows Kerberos Elevation of Privilege Vulnerability May 31, 2023 | CVSS7.8v3.1 | EPSS11.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35755HIGH | Windows Print Spooler Elevation of Privilege VulnerabilityWindows Print Spooler Elevation of Privilege Vulnerability May 31, 2023 | CVSS7.3v3.1 | EPSS9.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35754MEDIUM | Unified Write Filter Elevation of Privilege VulnerabilityUnified Write Filter Elevation of Privilege Vulnerability May 31, 2023 | CVSS6.7v3.1 | EPSS0.41% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35753HIGH | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution VulnerabilityWindows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability May 31, 2023 | CVSS8.1v3.1 | EPSS1.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35752HIGH | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution VulnerabilityWindows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability May 31, 2023 | CVSS8.1v3.1 | EPSS1.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35751HIGH | Windows Hyper-V Elevation of Privilege VulnerabilityWindows Hyper-V Elevation of Privilege Vulnerability May 31, 2023 | CVSS7.8v3.1 | EPSS5.46% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35750HIGH | Win32k Elevation of Privilege VulnerabilityWin32k Elevation of Privilege Vulnerability May 31, 2023 | CVSS7.8v3.1 | EPSS6.48% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35749HIGH | Windows Digital Media Receiver Elevation of Privilege VulnerabilityWindows Digital Media Receiver Elevation of Privilege Vulnerability May 31, 2023 | CVSS7.8v3.1 | EPSS0.545% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35748HIGH | HTTP.sys Denial of Service VulnerabilityHTTP.sys Denial of Service Vulnerability May 31, 2023 | CVSS7.5v3.1 | EPSS47.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35747MEDIUM | Windows Point-to-Point Protocol (PPP) Denial of Service VulnerabilityWindows Point-to-Point Protocol (PPP) Denial of Service Vulnerability May 31, 2023 | CVSS5.9v3.1 | EPSS1.68% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35746HIGH | Windows Digital Media Receiver Elevation of Privilege VulnerabilityWindows Digital Media Receiver Elevation of Privilege Vulnerability May 31, 2023 | CVSS7.8v3.1 | EPSS0.545% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35745HIGH | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution VulnerabilityWindows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability May 31, 2023 | CVSS8.1v3.1 | EPSS1.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35744CRITICAL | Windows Point-to-Point Protocol (PPP) Remote Code Execution VulnerabilityWindows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability May 31, 2023 | CVSS9.8v3.1 | EPSS1.98% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35743HIGH | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution VulnerabilityMicrosoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability CWE-94May 31, 2023 | CVSS7.8v3.1 | EPSS1.45% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35822HIGH | Windows Defender Credential Guard Security Feature Bypass VulnerabilityWindows Defender Credential Guard Security Feature Bypass Vulnerability. This CVE ID is unique from CVE-2022-34709. Aug 15, 2022 | CVSS7.1v3.1 | EPSS0.91% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-34711HIGH | Windows Defender Credential Guard Elevation of Privilege VulnerabilityWindows Defender Credential Guard Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-34705, CVE-2022-35771. Aug 15, 2022 | CVSS7.8v3.1 | EPSS0.816% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35820HIGH | Windows Bluetooth Driver Elevation of Privilege VulnerabilityWindows Bluetooth Driver Elevation of Privilege Vulnerability. Aug 9, 2022 | CVSS7.8v3.1 | EPSS0.557% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35795HIGH | Windows Error Reporting Service Elevation of Privilege VulnerabilityWindows Error Reporting Service Elevation of Privilege Vulnerability. Aug 9, 2022 | CVSS7.8v3.1 | EPSS0.654% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35794HIGH | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution VulnerabilityWindows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-34702, CVE-2022-34714, CVE-2022-35745, CVE-2022-35752, CVE-2022-35753, CVE-2022-35766, CVE-2022-35767. Aug 9, 2022 | CVSS8.1v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35793HIGH | Windows Print Spooler Elevation of Privilege VulnerabilityWindows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-35755. Aug 9, 2022 | CVSS7.3v3.1 | EPSS9.13% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35792HIGH | Storage Spaces Direct Elevation of Privilege VulnerabilityStorage Spaces Direct Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-35762, CVE-2022-35763, CVE-2022-35764, CVE-2022-35765. Aug 9, 2022 | CVSS7.8v3.1 | EPSS0.616% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35771HIGH | Windows Defender Credential Guard Elevation of Privilege VulnerabilityWindows Defender Credential Guard Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-34705. CWE-269Aug 9, 2022 | CVSS7.8v3.1 | EPSS0.809% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |