Windows 11 23h2
by Microsoft
Source repositories
CVEs (2,445)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-28253 | Med | 0.36 | 5.5 | 0.01 | Apr 11, 2023 | Windows Kernel Information Disclosure Vulnerability | ||
| CVE-2023-28228 | Med | 0.36 | 5.5 | 0.00 | Apr 11, 2023 | Windows Spoofing Vulnerability | ||
| CVE-2023-24862 | Med | 0.36 | 5.5 | 0.01 | Mar 14, 2023 | Windows Secure Channel Denial of Service Vulnerability | ||
| CVE-2023-23409 | Med | 0.36 | 5.5 | 0.00 | Mar 14, 2023 | Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability | ||
| CVE-2023-23394 | Med | 0.36 | 5.5 | 0.00 | Mar 14, 2023 | Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability | ||
| CVE-2023-1018 | Med | 0.36 | 5.5 | 0.06 | Feb 28, 2023 | An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM. | ||
| CVE-2023-21687 | Med | 0.36 | 5.5 | 0.00 | Feb 14, 2023 | HTTP.sys Information Disclosure Vulnerability | ||
| CVE-2023-21776 | Med | 0.36 | 5.5 | 0.01 | Jan 10, 2023 | Windows Kernel Information Disclosure Vulnerability | ||
| CVE-2023-21559 | Med | 0.36 | 5.5 | 0.01 | Jan 10, 2023 | Windows Cryptographic Information Disclosure Vulnerability | ||
| CVE-2023-21550 | Med | 0.36 | 5.5 | 0.01 | Jan 10, 2023 | Windows Cryptographic Information Disclosure Vulnerability | ||
| CVE-2023-21540 | Med | 0.36 | 5.5 | 0.01 | Jan 10, 2023 | Windows Cryptographic Information Disclosure Vulnerability | ||
| CVE-2022-44674 | Med | 0.36 | 5.5 | 0.01 | Dec 13, 2022 | Windows Bluetooth Driver Information Disclosure Vulnerability | ||
| CVE-2022-41074 | Med | 0.36 | 5.5 | 0.01 | Dec 13, 2022 | Windows Graphics Component Information Disclosure Vulnerability | ||
| CVE-2022-41098 | Med | 0.36 | 5.5 | 0.01 | Nov 9, 2022 | Windows GDI+ Information Disclosure Vulnerability | ||
| CVE-2022-41055 | Med | 0.36 | 5.5 | 0.01 | Nov 9, 2022 | Windows Human Interface Device Information Disclosure Vulnerability | ||
| CVE-2022-38043 | Med | 0.36 | 5.5 | 0.01 | Oct 11, 2022 | Windows Security Support Provider Interface Information Disclosure Vulnerability | ||
| CVE-2022-38026 | Med | 0.36 | 5.5 | 0.01 | Oct 11, 2022 | Windows DHCP Client Information Disclosure Vulnerability | ||
| CVE-2022-38025 | Med | 0.36 | 5.5 | 0.01 | Oct 11, 2022 | Windows Distributed File System (DFS) Information Disclosure Vulnerability | ||
| CVE-2022-37996 | Med | 0.36 | 5.5 | 0.01 | Oct 11, 2022 | Windows Kernel Memory Information Disclosure Vulnerability | ||
| CVE-2026-45595 | Med | 0.35 | 5.4 | 0.00 | Jun 9, 2026 | Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network. |
- risk 0.36cvss 5.5epss 0.01
Windows Kernel Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
Windows Spoofing Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Secure Channel Denial of Service Vulnerability
- risk 0.36cvss 5.5epss 0.00
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.06
An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.
- risk 0.36cvss 5.5epss 0.00
HTTP.sys Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Kernel Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Cryptographic Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Cryptographic Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Cryptographic Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Bluetooth Driver Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Graphics Component Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows GDI+ Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Human Interface Device Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Security Support Provider Interface Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows DHCP Client Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Distributed File System (DFS) Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Kernel Memory Information Disclosure Vulnerability
- risk 0.35cvss 5.4epss 0.00
Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.
Page 117 of 123