Windows 11 23h2
by Microsoft
Source repositories
CVEs (2,433)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-37981 | Med | 0.28 | 4.3 | 0.02 | Oct 11, 2022 | Windows Event Logging Service Denial of Service Vulnerability | ||
| CVE-2025-21214 | Med | 0.27 | 4.2 | 0.01 | Jan 14, 2025 | Windows BitLocker Information Disclosure Vulnerability | ||
| CVE-2025-21210 | Med | 0.27 | 4.2 | 0.01 | Jan 14, 2025 | Windows BitLocker Information Disclosure Vulnerability | ||
| CVE-2024-38143 | Med | 0.27 | 4.2 | 0.02 | Aug 13, 2024 | Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability | ||
| CVE-2024-28922 | Med | 0.27 | 4.1 | 0.01 | Apr 9, 2024 | Secure Boot Security Feature Bypass Vulnerability | ||
| CVE-2024-21304 | Med | 0.27 | 4.1 | 0.00 | Feb 13, 2024 | Trusted Compute Base Elevation of Privilege Vulnerability | ||
| CVE-2025-29839 | Med | 0.26 | 4.0 | 0.00 | May 13, 2025 | Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-45642 | Low | 0.25 | 3.9 | 0.00 | Jun 9, 2026 | Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack. | ||
| CVE-2025-49760 | Low | 0.23 | 3.5 | 0.01 | Jul 8, 2025 | External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-21249 | Low | 0.22 | 3.3 | 0.11 | Feb 10, 2026 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally. | ||
| CVE-2025-59284 | Low | 0.22 | 3.3 | 0.01 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally. | ||
| CVE-2025-21337 | Low | 0.21 | 3.3 | 0.01 | Feb 11, 2025 | Windows NTFS Elevation of Privilege Vulnerability | ||
| CVE-2023-21759 | Low | 0.21 | 3.3 | 0.01 | Jan 10, 2023 | Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability | ||
| CVE-2022-38022 | Low | 0.21 | 3.3 | 0.01 | Oct 11, 2022 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2025-59280 | Low | 0.20 | 3.1 | 0.00 | Oct 14, 2025 | Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network. | ||
| CVE-2025-21312 | Low | 0.16 | 2.4 | 0.01 | Jan 14, 2025 | Windows Smart Card Reader Information Disclosure Vulnerability | ||
| CVE-2025-59294 | Low | 0.14 | 2.1 | 0.01 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack. | ||
| CVE-2026-58638 | Med | 0.00 | 6.0 | 0.00 | Jul 14, 2026 | Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2026-58629 | Hig | 0.00 | 7.0 | 0.00 | Jul 14, 2026 | Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-56173 | Hig | 0.00 | 7.0 | 0.00 | Jul 14, 2026 | Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. |
- risk 0.28cvss 4.3epss 0.02
Windows Event Logging Service Denial of Service Vulnerability
- risk 0.27cvss 4.2epss 0.01
Windows BitLocker Information Disclosure Vulnerability
- risk 0.27cvss 4.2epss 0.01
Windows BitLocker Information Disclosure Vulnerability
- risk 0.27cvss 4.2epss 0.02
Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability
- risk 0.27cvss 4.1epss 0.01
Secure Boot Security Feature Bypass Vulnerability
- risk 0.27cvss 4.1epss 0.00
Trusted Compute Base Elevation of Privilege Vulnerability
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.
- risk 0.25cvss 3.9epss 0.00
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.
- risk 0.23cvss 3.5epss 0.01
External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a network.
- risk 0.22cvss 3.3epss 0.11
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
- risk 0.22cvss 3.3epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
- risk 0.21cvss 3.3epss 0.01
Windows NTFS Elevation of Privilege Vulnerability
- risk 0.21cvss 3.3epss 0.01
Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability
- risk 0.21cvss 3.3epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.20cvss 3.1epss 0.00
Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.
- risk 0.16cvss 2.4epss 0.01
Windows Smart Card Reader Information Disclosure Vulnerability
- risk 0.14cvss 2.1epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack.
- risk 0.00cvss 6.0epss 0.00
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
- risk 0.00cvss 7.0epss 0.00
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.0epss 0.00
Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.
Page 121 of 122