cbcvebase.

Microsoft Windows 11 24H2 vulnerabilities

1,692 known vulnerabilities affecting microsoft/windows_11_24h2.

Total CVEs
1,692
CISA KEV
40
actively exploited
Public exploits
29
Exploited in wild
46
Severity breakdown
CRITICAL37HIGH1215MEDIUM432LOW8

Vulnerabilities

Page 47 of 85
CVE-2025-62213P3HIGHCVSS 7.0fixed in 10.0.26100.70922025-11-11
CVE-2025-62213 [HIGH] CWE-416 CVE-2025-62213: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54911P3HIGHCVSS 7.3fixed in 10.0.26100.65082025-09-09
CVE-2025-54911 [HIGH] CWE-416 CVE-2025-54911: Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50364P3HIGHCVSS 7.3fixed in 10.0.26100.88752026-07-14
CVE-2026-50364 [HIGH] CWE-59 CVE-2026-50364: Improper link resolution before file access ('link following') in Windows Server Backup allows an au Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32149P3HIGHCVSS 7.3fixed in 10.0.26100.82462026-04-14
CVE-2026-32149 [HIGH] CWE-20 CVE-2026-32149: Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally. Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.
nvd
CVE-2026-20812P3MEDIUMCVSS 6.5fixed in 10.0.26100.76232026-01-13
CVE-2026-20812 [MEDIUM] CWE-20 CVE-2026-20812: Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authoriz Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network.
nvd
CVE-2024-43625P3HIGHCVSS 8.1fixed in 10.0.26100.23142024-11-12
CVE-2024-43625 [HIGH] CWE-416 CVE-2024-43625: Microsoft Windows VMSwitch Elevation of Privilege Vulnerability Microsoft Windows VMSwitch Elevation of Privilege Vulnerability
nvd
CVE-2024-49076P3HIGHCVSS 7.8fixed in 10.0.26100.26052024-12-12
CVE-2024-49076 [HIGH] CWE-287 CVE-2024-49076: Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
nvd
CVE-2024-38249P3HIGHCVSS 7.8fixed in 10.0.26100.17422024-09-10
CVE-2024-38249 [HIGH] CWE-416 CVE-2024-38249: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2024-49079P3HIGHCVSS 7.8fixed in 10.0.26100.26052024-12-12
CVE-2024-49079 [HIGH] CWE-416 CVE-2024-49079: Input Method Editor (IME) Remote Code Execution Vulnerability Input Method Editor (IME) Remote Code Execution Vulnerability
nvd
CVE-2025-55698P3HIGHCVSS 7.7fixed in 10.0.26100.68992025-10-14
CVE-2025-55698 [HIGH] CWE-476 CVE-2025-55698: Null pointer dereference in Windows DirectX allows an authorized attacker to deny service over a net Null pointer dereference in Windows DirectX allows an authorized attacker to deny service over a network.
nvd
CVE-2025-21358P3HIGHCVSS 7.8fixed in 10.0.26100.31942025-02-11
CVE-2025-21358 [HIGH] CWE-822 CVE-2025-21358: Windows Core Messaging Elevation of Privileges Vulnerability Windows Core Messaging Elevation of Privileges Vulnerability
nvd
CVE-2024-43626P3HIGHCVSS 7.8fixed in 10.0.26100.23142024-11-12
CVE-2024-43626 [HIGH] CWE-122 CVE-2024-43626: Windows Telephony Service Elevation of Privilege Vulnerability Windows Telephony Service Elevation of Privilege Vulnerability
nvd
CVE-2024-43556P3HIGHCVSS 7.8fixed in 10.0.26100.20332024-10-08
CVE-2024-43556 [HIGH] CWE-416 CVE-2024-43556: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2024-38247P3HIGHCVSS 7.8fixed in 10.0.26100.17422024-09-10
CVE-2024-38247 [HIGH] CWE-415 CVE-2024-38247: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2024-38135P3HIGHCVSS 7.8fixed in 10.0.26100.14572024-08-13
CVE-2024-38135 [HIGH] CWE-126 CVE-2024-38135: Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
nvd
CVE-2025-49689P3HIGHCVSS 7.8fixed in 10.0.26100.46522025-07-08
CVE-2025-49689 [HIGH] CWE-125 CVE-2025-49689: Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevat Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2024-43509P3HIGHCVSS 7.8fixed in 10.0.26100.20332024-10-08
CVE-2024-43509 [HIGH] CWE-416 CVE-2024-43509: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2025-21367P3HIGHCVSS 7.8fixed in 10.0.26100.31942025-02-11
CVE-2025-21367 [HIGH] CWE-416 CVE-2025-21367: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2024-43516P3HIGHCVSS 7.8fixed in 10.0.26100.20332024-10-08
CVE-2024-43516 [HIGH] CWE-822 CVE-2024-43516: Windows Secure Kernel Mode Elevation of Privilege Vulnerability Windows Secure Kernel Mode Elevation of Privilege Vulnerability
nvd
CVE-2024-38142P3HIGHCVSS 7.8fixed in 10.0.26100.14572024-08-13
CVE-2024-38142 [HIGH] CWE-122 CVE-2024-38142: Windows Secure Kernel Mode Elevation of Privilege Vulnerability Windows Secure Kernel Mode Elevation of Privilege Vulnerability
nvd