Windows 11 23h2
by Microsoft
Source repositories
CVEs (2,445)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-37983 | Hig | 0.51 | 7.8 | 0.00 | Oct 11, 2022 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | ||
| CVE-2022-37980 | Hig | 0.51 | 7.8 | 0.01 | Oct 11, 2022 | Windows DHCP Client Elevation of Privilege Vulnerability | ||
| CVE-2022-37979 | Hig | 0.51 | 7.8 | 0.01 | Oct 11, 2022 | Windows Hyper-V Elevation of Privilege Vulnerability | ||
| CVE-2022-37970 | Hig | 0.51 | 7.8 | 0.10 | Oct 11, 2022 | Windows DWM Core Library Elevation of Privilege Vulnerability | ||
| CVE-2022-33635 | Hig | 0.51 | 7.8 | 0.01 | Oct 11, 2022 | Windows GDI+ Remote Code Execution Vulnerability | ||
| CVE-2013-3900 | Med | 0.51 | 5.5 | 0.45 | KEV | Dec 11, 2013 | Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in all currently supported versions of Windows 10 and Windows… | |
| CVE-2026-20852 | Hig | 0.50 | 7.7 | 0.01 | Jan 13, 2026 | Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. | ||
| CVE-2026-20804 | Hig | 0.50 | 7.7 | 0.01 | Jan 13, 2026 | Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. | ||
| CVE-2025-59200 | Hig | 0.50 | 7.7 | 0.01 | Oct 14, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Client allows an unauthorized attacker to perform spoofing locally. | ||
| CVE-2025-53139 | Hig | 0.50 | 7.7 | 0.00 | Oct 14, 2025 | Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally. | ||
| CVE-2025-53722 | Hig | 0.50 | 7.5 | 0.18 | Aug 12, 2025 | Uncontrolled resource consumption in Windows Remote Desktop Services allows an unauthorized attacker to deny service over a network. | ||
| CVE-2025-47984 | Hig | 0.50 | 7.5 | 0.16 | Jul 8, 2025 | Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-29833 | Hig | 0.50 | 7.7 | 0.00 | May 13, 2025 | Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to execute code locally. | ||
| CVE-2024-43584 | Hig | 0.50 | 7.7 | 0.01 | Oct 8, 2024 | Windows Scripting Engine Security Feature Bypass Vulnerability | ||
| CVE-2023-21752 | Hig | 0.50 | 7.1 | 0.05 | Jan 10, 2023 | Windows Backup Service Elevation of Privilege Vulnerability | ||
| CVE-2022-37998 | Hig | 0.50 | 7.7 | 0.03 | Oct 11, 2022 | Windows Local Session Manager (LSM) Denial of Service Vulnerability | ||
| CVE-2022-37973 | Hig | 0.50 | 7.7 | 0.03 | Oct 11, 2022 | Windows Local Session Manager (LSM) Denial of Service Vulnerability | ||
| CVE-2026-61363 | Hig | 0.49 | 7.5 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-61352 | Hig | 0.49 | 7.5 | 0.00 | Aug 11, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-59134 | Hig | 0.49 | 7.5 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
- risk 0.51cvss 7.8epss 0.00
Microsoft DWM Core Library Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows DHCP Client Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Hyper-V Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.10
Windows DWM Core Library Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows GDI+ Remote Code Execution Vulnerability
- risk 0.51cvss 5.5epss 0.45
Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in all currently supported versions of Windows 10 and Windows…
- risk 0.50cvss 7.7epss 0.01
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
- risk 0.50cvss 7.7epss 0.01
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
- risk 0.50cvss 7.7epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Client allows an unauthorized attacker to perform spoofing locally.
- risk 0.50cvss 7.7epss 0.00
Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally.
- risk 0.50cvss 7.5epss 0.18
Uncontrolled resource consumption in Windows Remote Desktop Services allows an unauthorized attacker to deny service over a network.
- risk 0.50cvss 7.5epss 0.16
Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network.
- risk 0.50cvss 7.7epss 0.00
Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to execute code locally.
- risk 0.50cvss 7.7epss 0.01
Windows Scripting Engine Security Feature Bypass Vulnerability
- risk 0.50cvss 7.1epss 0.05
Windows Backup Service Elevation of Privilege Vulnerability
- risk 0.50cvss 7.7epss 0.03
Windows Local Session Manager (LSM) Denial of Service Vulnerability
- risk 0.50cvss 7.7epss 0.03
Windows Local Session Manager (LSM) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.01
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Page 64 of 123