Windows Server 2022 23H2

by Microsoft

Standard maintenance is sufficient

Windows Server 2022 23H2 has low exploitation rates. Attackers rarely target this software's known vulnerabilities.

What to do
  1. Keep automatic updates enabled
  2. No urgent action needed
  3. Review periodically as part of normal maintenance

What Attackers Target

Vulnerabilities with high exploit probability 6.9%
Confirmed actively exploited (CISA) 3.8%
Public exploit code available 0.0%
Based on 1500 known vulnerabilities. Percentages show the proportion that are actively dangerous — a low percentage means most vulnerabilities in this product are not being exploited.

Most Dangerous Vulnerabilities

CVE CVSS Exploit Probability Confirmed
CVE-2024-21412 8.1 93.8% Yes
CVE-2024-38112 7.5 92.6% Yes
CVE-2024-43451 6.5 90.3% Yes
CVE-2024-38063 9.8 89.9%
CVE-2024-49113 7.5 88.6%
CVE-2024-38077 9.8 86.3%
CVE-2024-49138 7.8 85.8% Yes
CVE-2024-30088 7.0 84.8% Yes
CVE-2024-26229 7.8 83.2%
CVE-2025-21333 7.8 81.3% Yes
CVE-2024-49112 9.8 80.7%
CVE-2024-38144 8.8 79.8%
CVE-2024-21338 7.8 79.1% Yes
CVE-2013-3900 5.5 78.1% Yes
CVE-2025-21293 8.8 75.8%
CVE-2025-59287 9.8 75.7% Yes
CVE-2024-38193 7.8 74.8% Yes
CVE-2025-21298 9.8 72.2%
CVE-2024-49039 8.8 63.7% Yes
CVE-2024-29988 8.8 62.8% Yes
15
/ 100
low-risk
Active Threat 11/50 · Low
Exploit Availability 4/50 · Minimal

Score uses Wilson score intervals to account for sample size. Products with few CVEs are scored conservatively.