Microsoft Windows 11 23H2 vulnerabilities

1,263 known vulnerabilities affecting microsoft/windows_11_23h2.

Total CVEs
1,263
CISA KEV
52
actively exploited
Public exploits
22
Exploited in wild
21
Severity breakdown
CRITICAL15HIGH884MEDIUM358LOW6

Vulnerabilities

Page 34 of 64
CVE-2025-21368HIGHCVSS 8.8fixed in 10.0.22631.48902025-02-11
CVE-2025-21368 [HIGH] CWE-122 CVE-2025-21368: Microsoft Digest Authentication Remote Code Execution Vulnerability Microsoft Digest Authentication Remote Code Execution Vulnerability
nvd
CVE-2025-21190HIGHCVSS 8.8fixed in 10.0.22631.48902025-02-11
CVE-2025-21190 [HIGH] CWE-122 CVE-2025-21190: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21358HIGHCVSS 7.8fixed in 10.0.22631.48902025-02-11
CVE-2025-21358 [HIGH] CWE-822 CVE-2025-21358: Windows Core Messaging Elevation of Privileges Vulnerability Windows Core Messaging Elevation of Privileges Vulnerability
nvd
CVE-2025-21375HIGHCVSS 7.8fixed in 10.0.22631.48902025-02-11
CVE-2025-21375 [HIGH] CWE-20 CVE-2025-21375: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-21419HIGHCVSS 7.1fixed in 10.0.22631.48902025-02-11
CVE-2025-21419 [HIGH] CWE-59 CVE-2025-21419: Windows Setup Files Cleanup Elevation of Privilege Vulnerability Windows Setup Files Cleanup Elevation of Privilege Vulnerability
nvd
CVE-2025-21181HIGHCVSS 7.5fixed in 10.0.22631.48902025-02-11
CVE-2025-21181 [HIGH] CWE-400 CVE-2025-21181: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21391HIGHCVSS 7.1KEVfixed in 10.0.22631.48902025-02-11
CVE-2025-21391 [HIGH] CWE-59 CVE-2025-21391: Windows Storage Elevation of Privilege Vulnerability Windows Storage Elevation of Privilege Vulnerability
nvd
CVE-2025-21418HIGHCVSS 7.8KEVfixed in 10.0.22631.48902025-02-11
CVE-2025-21418 [HIGH] CWE-122 CVE-2025-21418: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd
CVE-2025-21420HIGHCVSS 7.8≤ 10.0.22631.48902025-02-11
CVE-2025-21420 [HIGH] CWE-59 CVE-2025-21420: Windows Disk Cleanup Tool Elevation of Privilege Vulnerability Windows Disk Cleanup Tool Elevation of Privilege Vulnerability
nvd
CVE-2025-21184HIGHCVSS 7.0fixed in 10.0.22631.48902025-02-11
CVE-2025-21184 [HIGH] CWE-122 CVE-2025-21184: Windows Core Messaging Elevation of Privileges Vulnerability Windows Core Messaging Elevation of Privileges Vulnerability
nvd
CVE-2025-21201HIGHCVSS 8.8fixed in 10.0.22631.48902025-02-11
CVE-2025-21201 [HIGH] CWE-415 CVE-2025-21201: Windows Telephony Server Remote Code Execution Vulnerability Windows Telephony Server Remote Code Execution Vulnerability
nvd
CVE-2025-21351HIGHCVSS 7.5fixed in 10.0.22631.48902025-02-11
CVE-2025-21351 [HIGH] CWE-400 CVE-2025-21351: Windows Active Directory Domain Services API Denial of Service Vulnerability Windows Active Directory Domain Services API Denial of Service Vulnerability
nvd
CVE-2025-21200HIGHCVSS 8.8fixed in 10.0.22631.48902025-02-11
CVE-2025-21200 [HIGH] CWE-122 CVE-2025-21200: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21371HIGHCVSS 8.8fixed in 10.0.22631.48902025-02-11
CVE-2025-21371 [HIGH] CWE-122 CVE-2025-21371: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21347MEDIUMCVSS 6.0fixed in 10.0.22631.48902025-02-11
CVE-2025-21347 [MEDIUM] CWE-59 CVE-2025-21347: Windows Deployment Services Denial of Service Vulnerability Windows Deployment Services Denial of Service Vulnerability
nvd
CVE-2025-21212MEDIUMCVSS 6.5fixed in 10.0.22631.48902025-02-11
CVE-2025-21212 [MEDIUM] CWE-125 CVE-2025-21212: Internet Connection Sharing (ICS) Denial of Service Vulnerability Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd
CVE-2025-21216MEDIUMCVSS 6.5fixed in 10.0.22631.48902025-02-11
CVE-2025-21216 [MEDIUM] CWE-125 CVE-2025-21216: Internet Connection Sharing (ICS) Denial of Service Vulnerability Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd
CVE-2025-21349MEDIUMCVSS 6.8fixed in 10.0.22631.48902025-02-11
CVE-2025-21349 [MEDIUM] CWE-287 CVE-2025-21349: Windows Remote Desktop Configuration Service Tampering Vulnerability Windows Remote Desktop Configuration Service Tampering Vulnerability
nvd
CVE-2025-21254MEDIUMCVSS 6.5fixed in 10.0.22631.48902025-02-11
CVE-2025-21254 [MEDIUM] CWE-125 CVE-2025-21254: Internet Connection Sharing (ICS) Denial of Service Vulnerability Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd
CVE-2025-21352MEDIUMCVSS 6.5fixed in 10.0.22631.48902025-02-11
CVE-2025-21352 [MEDIUM] CWE-400 CVE-2025-21352: Internet Connection Sharing (ICS) Denial of Service Vulnerability Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd