VYPR

Windows 11 23h2

Sign in to watch

by Microsoft

CVEs (113)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2026-26177Hig0.467.00.00Apr 14, 2026Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-26174Hig0.467.00.00Apr 14, 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Service allows an authorized attacker to elevate privileges locally.
CVE-2026-26173Hig0.467.00.00Apr 14, 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-26166Hig0.467.00.00Apr 14, 2026Double free in Windows Shell allows an authorized attacker to elevate privileges locally.
CVE-2026-26165Hig0.467.00.00Apr 14, 2026Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
CVE-2026-26152Hig0.467.00.00Apr 14, 2026Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
CVE-2026-26151Hig0.467.10.00Apr 14, 2026Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-25184Hig0.467.00.00Apr 14, 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Applocker Filter Driver (applockerfltr.sys) allows an authorized attacker to elevate privileges locally.
CVE-2026-32151Med0.426.50.00Apr 14, 2026Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.
CVE-2026-27925Med0.426.50.00Apr 14, 2026Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network.
CVE-2026-26155Med0.426.50.00Apr 14, 2026Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
CVE-2026-32202Med0.414.30.08KEVApr 14, 2026Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-32088Med0.406.10.00Apr 14, 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Biometric Service allows an unauthorized attacker to bypass a security feature with a physical attack.
CVE-2026-32072Med0.406.20.00Apr 14, 2026Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.
CVE-2026-26169Med0.406.10.00Apr 14, 2026Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally.
CVE-2026-23670Med0.375.70.00Apr 14, 2026Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
CVE-2026-32218Med0.365.50.00Apr 14, 2026Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
CVE-2026-32217Med0.365.50.00Apr 14, 2026Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
CVE-2026-32215Med0.365.50.00Apr 14, 2026Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
CVE-2026-32214Med0.365.50.00Apr 14, 2026Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

Page 5 of 6