Windows 11 23h2
by Microsoft
Source repositories
CVEs (2,445)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-24084 | Hig | 0.55 | 8.4 | 0.01 | Mar 11, 2025 | Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally. | ||
| CVE-2024-49113 | Hig | 0.55 | 7.5 | 0.83 | Dec 12, 2024 | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | ||
| CVE-2024-49105 | Hig | 0.55 | 8.4 | 0.02 | Dec 12, 2024 | Remote Desktop Client Remote Code Execution Vulnerability | ||
| CVE-2024-38213 | Med | 0.55 | 6.5 | 0.14 | KEV | Aug 13, 2024 | Windows Mark of the Web Security Feature Bypass Vulnerability | |
| CVE-2024-37984 | Hig | 0.55 | 8.4 | 0.01 | Jul 9, 2024 | Secure Boot Security Feature Bypass Vulnerability | ||
| CVE-2024-30085 | Hig | 0.55 | 7.8 | 0.14 | Jun 11, 2024 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-29050 | Hig | 0.55 | 8.4 | 0.01 | Apr 9, 2024 | Windows Cryptographic Services Remote Code Execution Vulnerability | ||
| CVE-2024-21357 | Hig | 0.55 | 8.1 | 0.27 | Feb 13, 2024 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | ||
| CVE-2022-38044 | Hig | 0.55 | 7.8 | 0.56 | Oct 11, 2022 | Windows CD-ROM File System Driver Remote Code Execution Vulnerability | ||
| CVE-2025-59254 | Hig | 0.54 | 7.8 | 0.01 | Oct 14, 2025 | Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-49730 | Hig | 0.54 | 7.8 | 0.01 | Jul 8, 2025 | Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-49683 | Hig | 0.54 | 7.8 | 0.02 | Jul 8, 2025 | Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-47987 | Hig | 0.54 | 7.8 | 0.02 | Jul 8, 2025 | Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally. | ||
| CVE-2024-49122 | Hig | 0.54 | 8.1 | 0.20 | Dec 12, 2024 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||
| CVE-2024-43642 | Hig | 0.54 | 7.5 | 0.62 | Nov 12, 2024 | Windows SMB Denial of Service Vulnerability | ||
| CVE-2024-43574 | Hig | 0.54 | 8.3 | 0.01 | Oct 8, 2024 | Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability | ||
| CVE-2024-30038 | Hig | 0.54 | 7.8 | 0.03 | May 14, 2024 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2024-21407 | Hig | 0.54 | 8.1 | 0.16 | Mar 12, 2024 | Windows Hyper-V Remote Code Execution Vulnerability | ||
| CVE-2023-36606 | Hig | 0.54 | 7.5 | 0.67 | Oct 10, 2023 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2023-38039 | Hig | 0.54 | 7.5 | 0.62 | Sep 15, 2023 | When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an… |
- risk 0.55cvss 8.4epss 0.01
Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally.
- risk 0.55cvss 7.5epss 0.83
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
- risk 0.55cvss 8.4epss 0.02
Remote Desktop Client Remote Code Execution Vulnerability
- risk 0.55cvss 6.5epss 0.14
Windows Mark of the Web Security Feature Bypass Vulnerability
- risk 0.55cvss 8.4epss 0.01
Secure Boot Security Feature Bypass Vulnerability
- risk 0.55cvss 7.8epss 0.14
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
- risk 0.55cvss 8.4epss 0.01
Windows Cryptographic Services Remote Code Execution Vulnerability
- risk 0.55cvss 8.1epss 0.27
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- risk 0.55cvss 7.8epss 0.56
Windows CD-ROM File System Driver Remote Code Execution Vulnerability
- risk 0.54cvss 7.8epss 0.01
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
- risk 0.54cvss 7.8epss 0.01
Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally.
- risk 0.54cvss 7.8epss 0.02
Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally.
- risk 0.54cvss 7.8epss 0.02
Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally.
- risk 0.54cvss 8.1epss 0.20
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- risk 0.54cvss 7.5epss 0.62
Windows SMB Denial of Service Vulnerability
- risk 0.54cvss 8.3epss 0.01
Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability
- risk 0.54cvss 7.8epss 0.03
Win32k Elevation of Privilege Vulnerability
- risk 0.54cvss 8.1epss 0.16
Windows Hyper-V Remote Code Execution Vulnerability
- risk 0.54cvss 7.5epss 0.67
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.54cvss 7.5epss 0.62
When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an…
Page 20 of 123