Windows 11 23h2
by Microsoft
Source repositories
CVEs (2,445)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-61937 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61934 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61932 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61930 | Hig | 0.51 | 7.8 | 0.02 | Aug 11, 2026 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61926 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61925 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61923 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61367 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61365 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61364 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61359 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61358 | Hig | 0.51 | 7.8 | 0.04 | Aug 11, 2026 | Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61356 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61355 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61353 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61349 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-59127 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-56174 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-54984 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-48583 | Hig | 0.51 | 7.8 | 0.00 | Jun 9, 2026 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
- risk 0.51cvss 7.8epss 0.00
Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.02
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.04
Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Page 30 of 123