cbcvebase.

Microsoft Windows 11 23H2 vulnerabilities

1,546 known vulnerabilities affecting microsoft/windows_11_23h2.

Total CVEs
1,546
CISA KEV
53
actively exploited
Public exploits
37
Exploited in wild
63
Severity breakdown
CRITICAL24HIGH1099MEDIUM416LOW7

Vulnerabilities

Page 42 of 78
CVE-2025-49689P3HIGHCVSS 7.8fixed in 10.0.22631.56242025-07-08
CVE-2025-49689 [HIGH] CWE-125 CVE-2025-49689: Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevat Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2024-43509P3HIGHCVSS 7.8fixed in 10.0.22631.43172024-10-08
CVE-2024-43509 [HIGH] CWE-416 CVE-2024-43509: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2025-21367P3HIGHCVSS 7.8fixed in 10.0.22631.48902025-02-11
CVE-2025-21367 [HIGH] CWE-416 CVE-2025-21367: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2024-43516P3HIGHCVSS 7.8fixed in 10.0.22631.43172024-10-08
CVE-2024-43516 [HIGH] CWE-822 CVE-2024-43516: Windows Secure Kernel Mode Elevation of Privilege Vulnerability Windows Secure Kernel Mode Elevation of Privilege Vulnerability
nvd
CVE-2024-38142P3HIGHCVSS 7.8fixed in 10.0.22631.40372024-08-13
CVE-2024-38142 [HIGH] CWE-122 CVE-2024-38142: Windows Secure Kernel Mode Elevation of Privilege Vulnerability Windows Secure Kernel Mode Elevation of Privilege Vulnerability
nvd
CVE-2024-43514P3HIGHCVSS 7.8fixed in 10.0.22631.43172024-10-08
CVE-2024-43514 [HIGH] CWE-415 CVE-2024-43514: Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
nvd
CVE-2024-38253P3HIGHCVSS 7.8fixed in 10.0.22621.4169fixed in 10.0.22631.41692024-09-10
CVE-2024-38253 [HIGH] CWE-416 CVE-2024-38253: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2024-38252P3HIGHCVSS 7.8fixed in 10.0.22621.4169fixed in 10.0.22631.41692024-09-10
CVE-2024-38252 [HIGH] CWE-416 CVE-2024-38252: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2025-53805P3HIGHCVSS 7.5fixed in 10.0.22631.59092025-09-09
CVE-2025-53805 [HIGH] CWE-125 CVE-2025-53805: Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-21343P3HIGHCVSS 7.5fixed in 10.0.22631.47512025-01-14
CVE-2025-21343 [HIGH] CWE-269 CVE-2025-21343: Windows Web Threat Defense User Service Information Disclosure Vulnerability Windows Web Threat Defense User Service Information Disclosure Vulnerability
nvd
CVE-2024-43640P3HIGHCVSS 7.8fixed in 10.0.22631.44602024-11-12
CVE-2024-43640 [HIGH] CWE-415 CVE-2024-43640: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-21378P3HIGHCVSS 7.8fixed in 10.0.22631.47512025-01-14
CVE-2025-21378 [HIGH] CWE-122 CVE-2025-21378: Windows CSC Service Elevation of Privilege Vulnerability Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2024-43644P3HIGHCVSS 7.8fixed in 10.0.22631.44602024-11-12
CVE-2024-43644 [HIGH] CWE-125 CVE-2024-43644: Windows Client-Side Caching Elevation of Privilege Vulnerability Windows Client-Side Caching Elevation of Privilege Vulnerability
nvd
CVE-2024-43646P3HIGHCVSS 7.8fixed in 10.0.22631.44602024-11-12
CVE-2024-43646 [HIGH] CWE-822 CVE-2024-43646: Windows Secure Kernel Mode Elevation of Privilege Vulnerability Windows Secure Kernel Mode Elevation of Privilege Vulnerability
nvd
CVE-2024-43631P3HIGHCVSS 7.8fixed in 10.0.22631.44602024-11-12
CVE-2024-43631 [HIGH] CWE-822 CVE-2024-43631: Windows Secure Kernel Mode Elevation of Privilege Vulnerability Windows Secure Kernel Mode Elevation of Privilege Vulnerability
nvd
CVE-2024-43528P3HIGHCVSS 7.8fixed in 10.0.22631.43172024-10-08
CVE-2024-43528 [HIGH] CWE-122 CVE-2024-43528: Windows Secure Kernel Mode Elevation of Privilege Vulnerability Windows Secure Kernel Mode Elevation of Privilege Vulnerability
nvd
CVE-2026-25190P3HIGHCVSS 7.8fixed in 10.0.22631.67832026-03-10
CVE-2026-25190 [HIGH] CWE-426 CVE-2026-25190: Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally. Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-59194P3HIGHCVSS 7.0≤ 10.0.22631.60602025-10-14
CVE-2025-59194 [HIGH] CWE-908 CVE-2025-59194: Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-32716P3HIGHCVSS 7.8fixed in 10.0.22631.54722025-06-10
CVE-2025-32716 [HIGH] CWE-125 CVE-2025-32716: Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally. Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-49046P3HIGHCVSS 7.8fixed in 10.0.22631.44602024-11-12
CVE-2024-49046 [HIGH] CWE-367 CVE-2024-49046: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
Microsoft Windows 11 23H2 vulnerabilities | cvebase