Windows 11 24h2
by Microsoft
Source repositories
CVEs (1,923)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-23671 | Hig | 0.46 | 7.0 | 0.00 | Mar 10, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-23667 | Hig | 0.46 | 7.0 | 0.00 | Mar 10, 2026 | Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-21508 | Hig | 0.46 | 7.0 | 0.00 | Feb 10, 2026 | Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-21253 | Hig | 0.46 | 7.0 | 0.01 | Feb 10, 2026 | Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-21242 | Hig | 0.46 | 7.0 | 0.00 | Feb 10, 2026 | Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-21241 | Hig | 0.46 | 7.0 | 0.03 | Feb 10, 2026 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-21237 | Hig | 0.46 | 7.0 | 0.00 | Feb 10, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-21234 | Hig | 0.46 | 7.0 | 0.00 | Feb 10, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-21221 | Hig | 0.46 | 7.0 | 0.00 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20869 | Hig | 0.46 | 7.0 | 0.00 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20863 | Hig | 0.46 | 7.0 | 0.00 | Jan 13, 2026 | Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20842 | Hig | 0.46 | 7.0 | 0.00 | Jan 13, 2026 | Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20836 | Hig | 0.46 | 7.0 | 0.00 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20815 | Hig | 0.46 | 7.0 | 0.00 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20814 | Hig | 0.46 | 7.0 | 0.00 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20808 | Hig | 0.46 | 7.0 | 0.00 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-62573 | Hig | 0.46 | 7.0 | 0.00 | Dec 9, 2025 | Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-62570 | Hig | 0.46 | 7.1 | 0.00 | Dec 9, 2025 | Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally. | ||
| CVE-2025-62569 | Hig | 0.46 | 7.0 | 0.00 | Dec 9, 2025 | Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-62469 | Hig | 0.46 | 7.0 | 0.00 | Dec 9, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. |
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.01
Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.03
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.1epss 0.00
Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
Page 51 of 97