Microsoft Windows 11 24H2 vulnerabilities
1,692 known vulnerabilities affecting microsoft/windows_11_24h2.
Total CVEs
1,692
CISA KEV
40
actively exploited
Public exploits
29
Exploited in wild
46
Severity breakdown
CRITICAL37HIGH1215MEDIUM432LOW8
Vulnerabilities
Page 48 of 85
CVE-2024-43514P3HIGHCVSS 7.8fixed in 10.0.26100.20332024-10-08
CVE-2024-43514 [HIGH] CWE-415 CVE-2024-43514: Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
nvd
CVE-2024-38253P3HIGHCVSS 7.8fixed in 10.0.26100.17422024-09-10
CVE-2024-38253 [HIGH] CWE-416 CVE-2024-38253: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2024-38252P3HIGHCVSS 7.8fixed in 10.0.26100.17422024-09-10
CVE-2024-38252 [HIGH] CWE-416 CVE-2024-38252: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2025-53805P3HIGHCVSS 7.5fixed in 10.0.26100.65082025-09-09
CVE-2025-53805 [HIGH] CWE-125 CVE-2025-53805: Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny
Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-21343P3HIGHCVSS 7.5fixed in 10.0.26100.28942025-01-14
CVE-2025-21343 [HIGH] CWE-269 CVE-2025-21343: Windows Web Threat Defense User Service Information Disclosure Vulnerability
Windows Web Threat Defense User Service Information Disclosure Vulnerability
nvd
CVE-2025-21378P3HIGHCVSS 7.8fixed in 10.0.26100.28942025-01-14
CVE-2025-21378 [HIGH] CWE-122 CVE-2025-21378: Windows CSC Service Elevation of Privilege Vulnerability
Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2024-43644P3HIGHCVSS 7.8fixed in 10.0.26100.23142024-11-12
CVE-2024-43644 [HIGH] CWE-125 CVE-2024-43644: Windows Client-Side Caching Elevation of Privilege Vulnerability
Windows Client-Side Caching Elevation of Privilege Vulnerability
nvd
CVE-2024-43646P3HIGHCVSS 7.8fixed in 10.0.26100.23142024-11-12
CVE-2024-43646 [HIGH] CWE-822 CVE-2024-43646: Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
nvd
CVE-2024-43631P3HIGHCVSS 7.8fixed in 10.0.26100.23142024-11-12
CVE-2024-43631 [HIGH] CWE-822 CVE-2024-43631: Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
nvd
CVE-2024-43528P3HIGHCVSS 7.8fixed in 10.0.26100.20332024-10-08
CVE-2024-43528 [HIGH] CWE-122 CVE-2024-43528: Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
nvd
CVE-2026-25190P3HIGHCVSS 7.8fixed in 10.0.26100.79792026-03-10
CVE-2026-25190 [HIGH] CWE-426 CVE-2026-25190: Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally.
Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-59194P3HIGHCVSS 7.0fixed in 10.0.26100.68992025-10-14
CVE-2025-59194 [HIGH] CWE-908 CVE-2025-59194: Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges
Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-49046P3HIGHCVSS 7.8fixed in 10.0.26100.23142024-11-12
CVE-2024-49046 [HIGH] CWE-367 CVE-2024-49046: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2025-49694P3HIGHCVSS 7.8fixed in 10.0.26100.46522025-07-08
CVE-2025-49694 [HIGH] CWE-476 CVE-2025-49694: Null pointer dereference in Microsoft Brokering File System allows an authorized attacker to elevate
Null pointer dereference in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49686P3HIGHCVSS 7.8fixed in 10.0.26100.46522025-07-08
CVE-2025-49686 [HIGH] CWE-476 CVE-2025-49686: Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges local
Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-47985P3HIGHCVSS 7.8fixed in 10.0.26100.46522025-07-08
CVE-2025-47985 [HIGH] CWE-822 CVE-2025-47985: Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate priv
Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49661P3HIGHCVSS 7.8fixed in 10.0.26100.46522025-07-08
CVE-2025-49661 [HIGH] CWE-822 CVE-2025-49661: Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized
Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55230P3HIGHCVSS 7.8fixed in 10.0.26100.46522025-08-21
CVE-2025-55230 [HIGH] CWE-822 CVE-2025-55230: Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to eleva
Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32071P3HIGHCVSS 7.5fixed in 10.0.26100.82462026-04-14
CVE-2026-32071 [HIGH] CWE-476 CVE-2026-32071: Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an una
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-27738P3MEDIUMCVSS 6.5fixed in 10.0.26100.37752025-04-08
CVE-2025-27738 [MEDIUM] CWE-284 CVE-2025-27738: Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to dis
Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network.
nvd