ScriptMasterSkillet Answer to your questions:
1. Yes the KB takes precedence. We have a weird dance of both VC++2012/2013 runtimes being required. We pre-req on the 2013 runtime in Exchange SETUP, but UCMA installs the 2012 runtime.
2. Self explanatory you found the correct link.
3. Under our Cumulative Update support policy during extended support, we will retire support for Cumulative Update 22 in the near future. That means to get future updates for Exchange 2013, you will need to deploy the Cumulative Update 23. If you have applied the security update for Cumulative Update 22, you have the same fixes that were deployed in Cumulative Update 23 with the exception of the AD permissions changes we included in Cumulative Update 23. We cannot change AD permissions in a Security Update package because doing so requires SETUP /PrepareAD to be executed.