Microsoft Windows 11 23H2 vulnerabilities
1,546 known vulnerabilities affecting microsoft/windows_11_23h2.
Total CVEs
1,546
CISA KEV
53
actively exploited
Public exploits
37
Exploited in wild
63
Severity breakdown
CRITICAL24HIGH1099MEDIUM416LOW7
Vulnerabilities
Page 69 of 78
CVE-2025-55699P4MEDIUMCVSS 5.5≤ 10.0.22631.60602025-10-14
CVE-2025-55699 [MEDIUM] CWE-200 CVE-2025-55699: Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized at
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2025-59510P4MEDIUMCVSS 5.5fixed in 10.0.22631.61992025-11-11
CVE-2025-59510 [MEDIUM] CWE-59 CVE-2025-59510: Improper link resolution before file access ('link following') in Windows Routing and Remote Access
Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service locally.
nvd
CVE-2025-24068P4MEDIUMCVSS 5.5fixed in 10.0.22631.54722025-06-10
CVE-2025-24068 [MEDIUM] CWE-126 CVE-2025-24068: Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose in
Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2026-20939P4MEDIUMCVSS 5.5fixed in 10.0.22631.64912026-01-13
CVE-2026-20939 [MEDIUM] CWE-200 CVE-2026-20939: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-20937P4MEDIUMCVSS 5.5fixed in 10.0.22631.64912026-01-13
CVE-2026-20937 [MEDIUM] CWE-200 CVE-2026-20937: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42972P4MEDIUMCVSS 5.5fixed in 10.0.22631.72192026-06-09
CVE-2026-42972 [MEDIUM] CWE-200 CVE-2026-42972: Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized a
Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42971P4MEDIUMCVSS 5.5fixed in 10.0.22631.72192026-06-09
CVE-2026-42971 [MEDIUM] CWE-200 CVE-2026-42971: Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an a
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
nvd
CVE-2025-60706P4MEDIUMCVSS 5.5fixed in 10.0.22631.61992025-11-11
CVE-2025-60706 [MEDIUM] CWE-125 CVE-2025-60706: Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32085P4MEDIUMCVSS 5.5fixed in 10.0.22631.69362026-04-14
CVE-2026-32085 [MEDIUM] CWE-200 CVE-2026-32085: Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows a
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information locally.
nvd
CVE-2025-21340P4MEDIUMCVSS 5.5fixed in 10.0.22631.47512025-01-14
CVE-2025-21340 [MEDIUM] CWE-284 CVE-2025-21340: Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability
Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability
nvd
CVE-2025-59209P4MEDIUMCVSS 5.5≤ 10.0.22631.60602025-10-14
CVE-2025-59209 [MEDIUM] CWE-200 CVE-2025-59209: Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
nvd
CVE-2025-49684P4MEDIUMCVSS 5.5fixed in 10.0.22631.56242025-07-08
CVE-2025-49684 [MEDIUM] CWE-126 CVE-2025-49684: Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locall
Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2024-21362P4MEDIUMCVSS 5.5fixed in 10.0.22631.31552024-02-13
CVE-2024-21362 [MEDIUM] CWE-367 CVE-2024-21362: Windows Kernel Security Feature Bypass Vulnerability
Windows Kernel Security Feature Bypass Vulnerability
nvd
CVE-2026-32081P4MEDIUMCVSS 5.5fixed in 10.0.22631.69362026-04-14
CVE-2026-32081 [MEDIUM] CWE-200 CVE-2026-32081: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-24282P4MEDIUMCVSS 5.5fixed in 10.0.22631.67832026-03-10
CVE-2026-24282 [MEDIUM] CWE-125 CVE-2026-24282: Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose informa
Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42973P4MEDIUMCVSS 5.5fixed in 10.0.22631.72192026-06-09
CVE-2026-42973 [MEDIUM] CWE-200 CVE-2026-42973: Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an a
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42970P4MEDIUMCVSS 5.5fixed in 10.0.22631.72192026-06-09
CVE-2026-42970 [MEDIUM] CWE-200 CVE-2026-42970: Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an a
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42906P4MEDIUMCVSS 5.5fixed in 10.0.22631.72192026-06-09
CVE-2026-42906 [MEDIUM] CWE-200 CVE-2026-42906: Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized att
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42968P4MEDIUMCVSS 5.5fixed in 10.0.22631.72192026-06-09
CVE-2026-42968 [MEDIUM] CWE-125 CVE-2026-42968: Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose informatio
Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32084P4MEDIUMCVSS 5.5fixed in 10.0.22631.69362026-04-14
CVE-2026-32084 [MEDIUM] CWE-200 CVE-2026-32084: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd