Windows 11 23h2
by Microsoft
Source repositories
CVEs (2,422)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-34527 | Hig | 0.86 | 8.8 | 1.00 | KEV | Jul 2, 2021 | A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs;… | |
| CVE-2025-33053 | Hig | 0.79 | 8.8 | 0.85 | KEV | Jun 10, 2025 | External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network. | |
| CVE-2024-21412 | Hig | 0.78 | 8.1 | 0.95 | KEV | Feb 13, 2024 | Internet Shortcut Files Security Feature Bypass Vulnerability | |
| CVE-2025-33073 | Hig | 0.77 | 8.8 | 0.80 | KEV | Jun 10, 2025 | Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. | |
| CVE-2024-49039 | Hig | 0.76 | 8.8 | 0.14 | KEV | Nov 12, 2024 | Windows Task Scheduler Elevation of Privilege Vulnerability | |
| CVE-2024-21338 | Hig | 0.76 | 7.8 | 0.60 | KEV | Feb 13, 2024 | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2023-36025 | Hig | 0.76 | 8.8 | 0.88 | KEV | Nov 14, 2023 | Windows SmartScreen Security Feature Bypass Vulnerability | |
| CVE-2023-28252 | Hig | 0.76 | 7.8 | 0.49 | KEV | Apr 11, 2023 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2023-36884 | Hig | 0.75 | 7.5 | 0.99 | KEV | Jul 11, 2023 | Windows Search Remote Code Execution Vulnerability | |
| CVE-2023-21554 | Cri | 0.74 | 9.8 | 0.95 | Apr 11, 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||
| CVE-2024-43461 | Hig | 0.73 | 8.8 | 0.52 | KEV | Sep 10, 2024 | Windows MSHTML Platform Spoofing Vulnerability | |
| CVE-2024-29988 | Hig | 0.73 | 8.8 | 0.45 | KEV | Apr 9, 2024 | SmartScreen Prompt Security Feature Bypass Vulnerability | |
| CVE-2023-21674 | Hig | 0.73 | 8.8 | 0.42 | KEV | Jan 10, 2023 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | |
| CVE-2026-21510 | Hig | 0.71 | 8.8 | 0.26 | KEV | Feb 10, 2026 | Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. | |
| CVE-2022-41128 | Hig | 0.71 | 8.8 | 0.25 | KEV | Nov 9, 2022 | Windows Scripting Languages Remote Code Execution Vulnerability | |
| CVE-2026-21513 | Hig | 0.70 | 8.8 | 0.15 | KEV | Feb 10, 2026 | Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network. | |
| CVE-2025-29824 | Hig | 0.70 | 7.8 | 0.14 | KEV | Apr 8, 2025 | Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | |
| CVE-2025-21298 | Cri | 0.70 | 9.8 | 0.81 | Jan 14, 2025 | Windows OLE Remote Code Execution Vulnerability | ||
| CVE-2024-30040 | Hig | 0.70 | 8.8 | 0.04 | KEV | May 14, 2024 | Windows MSHTML Platform Security Feature Bypass Vulnerability | |
| CVE-2023-38545 | Cri | 0.70 | 9.8 | 0.78 | Oct 18, 2023 | This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255… |
- risk 0.86cvss 8.8epss 1.00
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs;…
- risk 0.79cvss 8.8epss 0.85
External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.
- risk 0.78cvss 8.1epss 0.95
Internet Shortcut Files Security Feature Bypass Vulnerability
- risk 0.77cvss 8.8epss 0.80
Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
- risk 0.76cvss 8.8epss 0.14
Windows Task Scheduler Elevation of Privilege Vulnerability
- risk 0.76cvss 7.8epss 0.60
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.76cvss 8.8epss 0.88
Windows SmartScreen Security Feature Bypass Vulnerability
- risk 0.76cvss 7.8epss 0.49
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- risk 0.75cvss 7.5epss 0.99
Windows Search Remote Code Execution Vulnerability
- risk 0.74cvss 9.8epss 0.95
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- risk 0.73cvss 8.8epss 0.52
Windows MSHTML Platform Spoofing Vulnerability
- risk 0.73cvss 8.8epss 0.45
SmartScreen Prompt Security Feature Bypass Vulnerability
- risk 0.73cvss 8.8epss 0.42
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
- risk 0.71cvss 8.8epss 0.26
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.71cvss 8.8epss 0.25
Windows Scripting Languages Remote Code Execution Vulnerability
- risk 0.70cvss 8.8epss 0.15
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.70cvss 7.8epss 0.14
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
- risk 0.70cvss 9.8epss 0.81
Windows OLE Remote Code Execution Vulnerability
- risk 0.70cvss 8.8epss 0.04
Windows MSHTML Platform Security Feature Bypass Vulnerability
- risk 0.70cvss 9.8epss 0.78
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255…
Page 1 of 122