cbcvebase.

Microsoft Windows 11 23H2 vulnerabilities

1,546 known vulnerabilities affecting microsoft/windows_11_23h2.

Total CVEs
1,546
CISA KEV
53
actively exploited
Public exploits
37
Exploited in wild
63
Severity breakdown
CRITICAL24HIGH1099MEDIUM416LOW7

Vulnerabilities

Page 12 of 78
CVE-2025-26663P3HIGHCVSS 8.1fixed in 10.0.22631.51892025-04-08
CVE-2025-26663 [HIGH] CWE-416 CVE-2025-26663: Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attack Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21294P3HIGHCVSS 8.1fixed in 10.0.22631.47512025-01-14
CVE-2025-21294 [HIGH] CWE-591 CVE-2025-21294: Microsoft Digest Authentication Remote Code Execution Vulnerability Microsoft Digest Authentication Remote Code Execution Vulnerability
nvd
CVE-2026-40415P3HIGHCVSS 8.1fixed in 10.0.22631.70792026-05-12
CVE-2026-40415 [HIGH] CWE-416 CVE-2026-40415: Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network. Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-45635P3HIGHCVSS 8.1fixed in 10.0.22631.72192026-06-09
CVE-2026-45635 [HIGH] CWE-843 CVE-2026-45635: Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-45599P3HIGHCVSS 8.1fixed in 10.0.22631.72192026-06-09
CVE-2026-45599 [HIGH] CWE-416 CVE-2026-45599: Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21204P3HIGHCVSS 7.8fixed in 10.0.22631.51892025-04-08
CVE-2025-21204 [HIGH] CWE-59 CVE-2025-21204: Improper link resolution before file access ('link following') in Windows Update Stack allows an aut Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-33829P4MEDIUMCVSS 4.3PoCfixed in 10.0.22631.69362026-04-14
CVE-2026-33829 [MEDIUM] CWE-200 CVE-2026-33829: Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauth Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2024-26166P3HIGHCVSS 8.8fixed in 10.0.22631.32962024-03-12
CVE-2024-26166 [HIGH] CWE-122 CVE-2024-26166: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21450P3HIGHCVSS 8.8fixed in 10.0.22631.34472024-03-12
CVE-2024-21450 [HIGH] CWE-190 CVE-2024-21450: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21440P3HIGHCVSS 8.8fixed in 10.0.22631.34472024-03-12
CVE-2024-21440 [HIGH] CWE-197 CVE-2024-21440: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2024-26162P3HIGHCVSS 8.8fixed in 10.0.22631.32962024-03-12
CVE-2024-26162 [HIGH] CWE-681 CVE-2024-26162: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2026-24289P3HIGHCVSS 7.8fixed in 10.0.22631.67832026-03-10
CVE-2026-24289 [HIGH] CWE-416 CVE-2026-24289: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-26210P3HIGHCVSS 8.8fixed in 10.0.22631.34472024-04-09
CVE-2024-26210 [HIGH] CWE-122 CVE-2024-26210: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-26244P3HIGHCVSS 8.8fixed in 10.0.22631.34472024-04-09
CVE-2024-26244 [HIGH] CWE-191 CVE-2024-26244: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-26159P3HIGHCVSS 8.8fixed in 10.0.22631.34472024-03-12
CVE-2024-26159 [HIGH] CWE-122 CVE-2024-26159: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2024-21451P3HIGHCVSS 8.8fixed in 10.0.22631.34472024-03-12
CVE-2024-21451 [HIGH] CWE-197 CVE-2024-21451: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2024-21444P3HIGHCVSS 8.8fixed in 10.0.22631.34472024-03-12
CVE-2024-21444 [HIGH] CWE-190 CVE-2024-21444: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21441P3HIGHCVSS 8.8fixed in 10.0.22631.34472024-03-12
CVE-2024-21441 [HIGH] CWE-190 CVE-2024-21441: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-26161P3HIGHCVSS 8.8fixed in 10.0.22631.34472024-03-12
CVE-2024-26161 [HIGH] CWE-122 CVE-2024-26161: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21370P3HIGHCVSS 8.8fixed in 10.0.22631.31552024-02-13
CVE-2024-21370 [HIGH] CWE-122 CVE-2024-21370: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
Microsoft Windows 11 23H2 vulnerabilities | cvebase