Windows 11 23h2
by Microsoft
Source repositories
CVEs (2,445)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21677 | Hig | 0.49 | 7.5 | 0.02 | Jan 10, 2023 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | ||
| CVE-2023-21557 | Hig | 0.49 | 7.5 | 0.02 | Jan 10, 2023 | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | ||
| CVE-2023-21539 | Hig | 0.49 | 7.5 | 0.01 | Jan 10, 2023 | Windows Authentication Remote Code Execution Vulnerability | ||
| CVE-2023-21527 | Hig | 0.49 | 7.5 | 0.02 | Jan 10, 2023 | Windows iSCSI Service Denial of Service Vulnerability | ||
| CVE-2022-41118 | Hig | 0.49 | 7.5 | 0.01 | Nov 9, 2022 | Windows Scripting Languages Remote Code Execution Vulnerability | ||
| CVE-2022-41058 | Hig | 0.49 | 7.5 | 0.02 | Nov 9, 2022 | Windows Network Address Translation (NAT) Denial of Service Vulnerability | ||
| CVE-2022-41056 | Hig | 0.49 | 7.5 | 0.02 | Nov 9, 2022 | Network Policy Server (NPS) RADIUS Protocol Denial of Service Vulnerability | ||
| CVE-2022-41053 | Hig | 0.49 | 7.5 | 0.02 | Nov 9, 2022 | Windows Kerberos Denial of Service Vulnerability | ||
| CVE-2022-38041 | Hig | 0.49 | 7.5 | 0.02 | Oct 11, 2022 | Windows Secure Channel Denial of Service Vulnerability | ||
| CVE-2022-37978 | Hig | 0.49 | 7.5 | 0.01 | Oct 11, 2022 | Windows Active Directory Certificate Services Security Feature Bypass | ||
| CVE-2022-33645 | Hig | 0.49 | 7.5 | 0.02 | Oct 11, 2022 | Windows TCP/IP Driver Denial of Service Vulnerability | ||
| CVE-2026-40414 | Hig | 0.48 | 7.4 | 0.01 | May 12, 2026 | Windows TCP/IP Denial of Service Vulnerability | ||
| CVE-2026-40413 | Hig | 0.48 | 7.4 | 0.00 | May 12, 2026 | Windows TCP/IP Denial of Service Vulnerability | ||
| CVE-2026-32202 | Med | 0.48 | 4.3 | 0.64 | KEV | Apr 14, 2026 | Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. | |
| CVE-2026-32156 | Hig | 0.48 | 7.4 | 0.00 | Apr 14, 2026 | Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-21235 | Hig | 0.48 | 7.3 | 0.01 | Feb 10, 2026 | Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20853 | Hig | 0.48 | 7.4 | 0.00 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-20844 | Hig | 0.48 | 7.4 | 0.00 | Jan 13, 2026 | Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-20805 | Med | 0.48 | 5.5 | 0.05 | KEV | Jan 13, 2026 | Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. | |
| CVE-2025-55687 | Hig | 0.48 | 7.4 | 0.00 | Oct 14, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File System (ReFS) allows an unauthorized attacker to elevate privileges locally. |
- risk 0.49cvss 7.5epss 0.02
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
Windows Authentication Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows iSCSI Service Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
Windows Scripting Languages Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Network Address Translation (NAT) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Network Policy Server (NPS) RADIUS Protocol Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Kerberos Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Secure Channel Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
Windows Active Directory Certificate Services Security Feature Bypass
- risk 0.49cvss 7.5epss 0.02
Windows TCP/IP Driver Denial of Service Vulnerability
- risk 0.48cvss 7.4epss 0.01
Windows TCP/IP Denial of Service Vulnerability
- risk 0.48cvss 7.4epss 0.00
Windows TCP/IP Denial of Service Vulnerability
- risk 0.48cvss 4.3epss 0.64
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
- risk 0.48cvss 7.4epss 0.00
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to execute code locally.
- risk 0.48cvss 7.3epss 0.01
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- risk 0.48cvss 7.4epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate privileges locally.
- risk 0.48cvss 7.4epss 0.00
Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.
- risk 0.48cvss 5.5epss 0.05
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
- risk 0.48cvss 7.4epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File System (ReFS) allows an unauthorized attacker to elevate privileges locally.
Page 73 of 123