Windows 11 23h2
by Microsoft
Source repositories
CVEs (2,440)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-32046 | Hig | 0.63 | 7.8 | 0.10 | KEV | Jul 11, 2023 | Windows MSHTML Platform Elevation of Privilege Vulnerability | |
| CVE-2023-21823 | Hig | 0.63 | 7.8 | 0.06 | KEV | Feb 14, 2023 | Windows Graphics Component Remote Code Execution Vulnerability | |
| CVE-2022-41125 | Hig | 0.63 | 7.8 | 0.03 | KEV | Nov 9, 2022 | Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | |
| CVE-2022-41033 | Hig | 0.63 | 7.8 | 0.02 | KEV | Oct 11, 2022 | Windows COM+ Event System Service Elevation of Privilege Vulnerability | |
| CVE-2026-42904 | Cri | 0.62 | 9.6 | 0.00 | Jun 9, 2026 | Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network. | ||
| CVE-2025-24054 | Med | 0.62 | 6.5 | 0.59 | KEV | Mar 11, 2025 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | |
| CVE-2025-21293 | Hig | 0.62 | 8.8 | 0.19 | Jan 14, 2025 | Active Directory Domain Services Elevation of Privilege Vulnerability | ||
| CVE-2025-62215 | Hig | 0.61 | 7.0 | 0.06 | KEV | Nov 11, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
| CVE-2024-43451 | Med | 0.61 | 6.5 | 0.82 | KEV | Nov 12, 2024 | NTLM Hash Disclosure Spoofing Vulnerability | |
| CVE-2026-40402 | Cri | 0.60 | 9.3 | 0.00 | May 12, 2026 | Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2025-53778 | Hig | 0.60 | 8.8 | 0.38 | Aug 12, 2025 | Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2024-38144 | Hig | 0.60 | 8.8 | 0.32 | Aug 13, 2024 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | ||
| CVE-2023-35628 | Hig | 0.60 | 8.1 | 0.93 | Dec 12, 2023 | Windows MSHTML Platform Remote Code Execution Vulnerability | ||
| CVE-2022-41076 | Hig | 0.60 | 8.5 | 0.62 | Dec 13, 2022 | PowerShell Remote Code Execution Vulnerability | ||
| CVE-2026-45602 | Cri | 0.59 | 9.1 | 0.00 | Jun 9, 2026 | No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network. | ||
| CVE-2025-55234 | Hig | 0.59 | 8.8 | 0.20 | Sep 9, 2025 | SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks. The SMB Server already supports mechanisms for… | ||
| CVE-2025-54918 | Hig | 0.59 | 8.8 | 0.19 | Sep 9, 2025 | Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-50171 | Cri | 0.59 | 9.1 | 0.01 | Aug 12, 2025 | Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2024-20674 | Hig | 0.59 | 8.8 | 0.17 | Jan 9, 2024 | Windows Kerberos Security Feature Bypass Vulnerability | ||
| CVE-2023-36017 | Hig | 0.59 | 8.8 | 0.25 | Nov 14, 2023 | Windows Scripting Engine Memory Corruption Vulnerability |
- risk 0.63cvss 7.8epss 0.10
Windows MSHTML Platform Elevation of Privilege Vulnerability
- risk 0.63cvss 7.8epss 0.06
Windows Graphics Component Remote Code Execution Vulnerability
- risk 0.63cvss 7.8epss 0.03
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
- risk 0.63cvss 7.8epss 0.02
Windows COM+ Event System Service Elevation of Privilege Vulnerability
- risk 0.62cvss 9.6epss 0.00
Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.
- risk 0.62cvss 6.5epss 0.59
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
- risk 0.62cvss 8.8epss 0.19
Active Directory Domain Services Elevation of Privilege Vulnerability
- risk 0.61cvss 7.0epss 0.06
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.61cvss 6.5epss 0.82
NTLM Hash Disclosure Spoofing Vulnerability
- risk 0.60cvss 9.3epss 0.00
Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.
- risk 0.60cvss 8.8epss 0.38
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
- risk 0.60cvss 8.8epss 0.32
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
- risk 0.60cvss 8.1epss 0.93
Windows MSHTML Platform Remote Code Execution Vulnerability
- risk 0.60cvss 8.5epss 0.62
PowerShell Remote Code Execution Vulnerability
- risk 0.59cvss 9.1epss 0.00
No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.
- risk 0.59cvss 8.8epss 0.20
SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks. The SMB Server already supports mechanisms for…
- risk 0.59cvss 8.8epss 0.19
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
- risk 0.59cvss 9.1epss 0.01
Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.
- risk 0.59cvss 8.8epss 0.17
Windows Kerberos Security Feature Bypass Vulnerability
- risk 0.59cvss 8.8epss 0.25
Windows Scripting Engine Memory Corruption Vulnerability
Page 6 of 122