cbcvebase.

Microsoft Windows 11 24H2 vulnerabilities

1,692 known vulnerabilities affecting microsoft/windows_11_24h2.

Total CVEs
1,692
CISA KEV
40
actively exploited
Public exploits
29
Exploited in wild
46
Severity breakdown
CRITICAL37HIGH1215MEDIUM432LOW8

Vulnerabilities

Page 34 of 85
CVE-2026-42978P3HIGHCVSS 7.8fixed in 10.0.26100.86552026-06-09
CVE-2026-42978 [HIGH] CWE-362 CVE-2026-42978: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32089P3HIGHCVSS 7.8fixed in 10.0.26100.82462026-04-14
CVE-2026-32089 [HIGH] CWE-362 CVE-2026-32089: Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges lo Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50311P3HIGHCVSS 7.8fixed in 10.0.26100.88752026-07-14
CVE-2026-50311 [HIGH] CWE-284 CVE-2026-50311: Improper access control in Windows Server allows an authorized attacker to elevate privileges locall Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59502P3HIGHCVSS 7.5fixed in 10.0.26100.65082025-10-14
CVE-2025-59502 [HIGH] CWE-400 CVE-2025-59502: Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker t Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50425P3HIGHCVSS 7.8fixed in 10.0.26100.88752026-07-14
CVE-2026-50425 [HIGH] CWE-416 CVE-2026-50425: Use after free in Windows Internal System User Profile allows an authorized attacker to elevate priv Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54109P3HIGHCVSS 7.8fixed in 10.0.26100.88752026-07-14
CVE-2026-54109 [HIGH] CWE-122 CVE-2026-54109: Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
nvd
CVE-2026-50466P3HIGHCVSS 7.8fixed in 10.0.26100.88752026-07-14
CVE-2026-50466 [HIGH] CWE-416 CVE-2026-50466: Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-27916P3HIGHCVSS 7.8fixed in 10.0.26100.82462026-04-14
CVE-2026-27916 [HIGH] CWE-416 CVE-2026-27916: Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker t Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-64661P3HIGHCVSS 7.8fixed in 10.0.26100.73922025-12-09
CVE-2025-64661 [HIGH] CWE-362 CVE-2025-64661: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50677P3HIGHCVSS 7.8fixed in 10.0.26100.88752026-07-14
CVE-2026-50677 [HIGH] CWE-362 CVE-2026-50677: Use after free in Windows Media allows an authorized attacker to elevate privileges locally. Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-27923P3HIGHCVSS 7.8fixed in 10.0.26100.82462026-04-14
CVE-2026-27923 [HIGH] CWE-416 CVE-2026-27923: Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58602P3HIGHCVSS 7.8fixed in 10.0.26100.88752026-07-14
CVE-2026-58602 [HIGH] CWE-416 CVE-2026-58602: Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges loc Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49171P3HIGHCVSS 7.8fixed in 10.0.26100.88752026-07-14
CVE-2026-49171 [HIGH] CWE-416 CVE-2026-49171: Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges local Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50405P3HIGHCVSS 7.8fixed in 10.0.26100.88752026-07-14
CVE-2026-50405 [HIGH] CWE-1220 CVE-2026-50405: Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32160P3HIGHCVSS 7.8fixed in 10.0.26100.82462026-04-14
CVE-2026-32160 [HIGH] CWE-362 CVE-2026-32160: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32159P3HIGHCVSS 7.8fixed in 10.0.26100.82462026-04-14
CVE-2026-32159 [HIGH] CWE-362 CVE-2026-32159: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50393P3HIGHCVSS 7.8fixed in 10.0.26100.88752026-07-14
CVE-2026-50393 [HIGH] CWE-416 CVE-2026-50393: Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges lo Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50396P3HIGHCVSS 7.8fixed in 10.0.26100.88752026-07-14
CVE-2026-50396 [HIGH] CWE-416 CVE-2026-50396: Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges lo Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32158P3HIGHCVSS 7.8fixed in 10.0.26100.82462026-04-14
CVE-2026-32158 [HIGH] CWE-362 CVE-2026-32158: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32153P3HIGHCVSS 7.8fixed in 10.0.26100.82462026-04-14
CVE-2026-32153 [HIGH] CWE-362 CVE-2026-32153: Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges local Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows 11 24H2 vulnerabilities | cvebase