Windows Server 2022 False Positive Vulnerabilities are Showing in Vulnerability Management
search cancel

Windows Server 2022 False Positive Vulnerabilities are Showing in Vulnerability Management

book

Article ID: 437262

calendar_today

Updated On:

Products

Carbon Black Cloud Workload

Issue/Introduction

On Windows Server 2022 machines some vulnerabilities are showing up when they are already patched

Environment

  • Carbon Black Cloud Console: April 2026
  • Windows OS: Windows Server 2022 21H2

Cause

  • There are two different versions of Server 2022, 21H2 with GUI, and 23H2 Server Core.
  • The vulnerability scanner may report 23H2 vulnerabilities on 21H2 systems due to differing patch numbers for the same issue.

Resolution

  • Permanent Fix: A backend fix should be applied in Quarter 2 of 2026
  • Workaround: Until then if the vulnerability is a False Positive it can be dismissed

Additional Information

CRE-23715