Windows 11 23h2
by Microsoft
Source repositories
CVEs (2,445)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-38031 | Hig | 0.57 | 8.8 | 0.02 | Oct 11, 2022 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2022-38016 | Hig | 0.57 | 8.8 | 0.00 | Oct 11, 2022 | Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | ||
| CVE-2022-37982 | Hig | 0.57 | 8.8 | 0.02 | Oct 11, 2022 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2022-37975 | Hig | 0.57 | 8.8 | 0.02 | Oct 11, 2022 | Windows Group Policy Elevation of Privilege Vulnerability | ||
| CVE-2022-23257 | Hig | 0.57 | 8.8 | 0.01 | Apr 15, 2022 | Windows Hyper-V Remote Code Execution Vulnerability | ||
| CVE-2025-9491 | Hig | 0.56 | 7.8 | 0.69 | Aug 26, 2025 | Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target… | ||
| CVE-2025-48822 | Hig | 0.56 | 8.6 | 0.01 | Jul 8, 2025 | Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-27737 | Hig | 0.56 | 8.6 | 0.01 | Apr 8, 2025 | Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally. | ||
| CVE-2023-36563 | Med | 0.56 | 6.5 | 0.21 | KEV | Oct 10, 2023 | Microsoft WordPad Information Disclosure Vulnerability | |
| CVE-2023-28302 | Hig | 0.56 | 7.5 | 0.93 | Apr 11, 2023 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2023-21769 | Hig | 0.56 | 7.5 | 0.89 | Apr 11, 2023 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2023-21758 | Hig | 0.56 | 7.5 | 0.93 | Jan 10, 2023 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | ||
| CVE-2023-21547 | Hig | 0.56 | 7.5 | 0.89 | Jan 10, 2023 | Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability | ||
| CVE-2026-45641 | Hig | 0.55 | 8.4 | 0.00 | Jun 9, 2026 | Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-45607 | Hig | 0.55 | 8.4 | 0.00 | Jun 9, 2026 | Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-44810 | Hig | 0.55 | 8.4 | 0.00 | Jun 9, 2026 | Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-32162 | Hig | 0.55 | 8.4 | 0.02 | Apr 14, 2026 | Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-32091 | Hig | 0.55 | 8.4 | 0.00 | Apr 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2025-33067 | Hig | 0.55 | 8.4 | 0.00 | Jun 10, 2025 | Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2025-26678 | Hig | 0.55 | 8.4 | 0.01 | Apr 8, 2025 | Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally. |
- risk 0.57cvss 8.8epss 0.02
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.00
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Group Policy Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.01
Windows Hyper-V Remote Code Execution Vulnerability
- risk 0.56cvss 7.8epss 0.69
Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target…
- risk 0.56cvss 8.6epss 0.01
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
- risk 0.56cvss 8.6epss 0.01
Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally.
- risk 0.56cvss 6.5epss 0.21
Microsoft WordPad Information Disclosure Vulnerability
- risk 0.56cvss 7.5epss 0.93
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.56cvss 7.5epss 0.89
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.56cvss 7.5epss 0.93
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
- risk 0.56cvss 7.5epss 0.89
Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability
- risk 0.55cvss 8.4epss 0.00
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
- risk 0.55cvss 8.4epss 0.00
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
- risk 0.55cvss 8.4epss 0.00
Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally.
- risk 0.55cvss 8.4epss 0.02
Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally.
- risk 0.55cvss 8.4epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
- risk 0.55cvss 8.4epss 0.00
Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
- risk 0.55cvss 8.4epss 0.01
Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally.
Page 19 of 123