Windows 11 24h2
by Microsoft
CVEs (1,910)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-21226 | Med | 0.43 | 6.6 | 0.01 | Jan 14, 2025 | Windows Digital Media Elevation of Privilege Vulnerability | ||
| CVE-2024-49111 | Med | 0.43 | 6.6 | 0.01 | Dec 12, 2024 | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | ||
| CVE-2024-49109 | Med | 0.43 | 6.6 | 0.01 | Dec 12, 2024 | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | ||
| CVE-2024-49101 | Med | 0.43 | 6.6 | 0.01 | Dec 12, 2024 | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | ||
| CVE-2024-49094 | Med | 0.43 | 6.6 | 0.01 | Dec 12, 2024 | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | ||
| CVE-2024-49081 | Med | 0.43 | 6.6 | 0.01 | Dec 12, 2024 | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | ||
| CVE-2026-65794 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-65785 | Med | 0.42 | 6.5 | 0.00 | Aug 11, 2026 | Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network. | ||
| CVE-2026-62782 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-62750 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network. | ||
| CVE-2026-62708 | Med | 0.42 | 6.4 | 0.00 | Aug 11, 2026 | Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. | ||
| CVE-2026-61924 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-61921 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-61918 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-61345 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. | ||
| CVE-2026-59138 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. | ||
| CVE-2026-42907 | Med | 0.42 | 6.5 | 0.01 | Jun 9, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally. | ||
| CVE-2026-42903 | Med | 0.42 | 6.5 | 0.01 | Jun 9, 2026 | Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network. | ||
| CVE-2026-35422 | Med | 0.42 | 6.5 | 0.01 | May 12, 2026 | Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network. | ||
| CVE-2026-32151 | Med | 0.42 | 6.5 | 0.01 | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network. |
- risk 0.43cvss 6.6epss 0.01
Windows Digital Media Elevation of Privilege Vulnerability
- risk 0.43cvss 6.6epss 0.01
Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
- risk 0.43cvss 6.6epss 0.01
Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
- risk 0.43cvss 6.6epss 0.01
Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
- risk 0.43cvss 6.6epss 0.01
Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
- risk 0.43cvss 6.6epss 0.01
Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
- risk 0.42cvss 6.5epss 0.01
Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.00
Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.
- risk 0.42cvss 6.4epss 0.00
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.01
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.
- risk 0.42cvss 6.5epss 0.01
Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.01
Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network.
- risk 0.42cvss 6.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.
Page 61 of 96