Microsoft Windows 11 24H2 vulnerabilities
1,692 known vulnerabilities affecting microsoft/windows_11_24h2.
Total CVEs
1,692
CISA KEV
40
actively exploited
Public exploits
29
Exploited in wild
46
Severity breakdown
CRITICAL37HIGH1215MEDIUM432LOW8
Vulnerabilities
Page 49 of 85
CVE-2026-35416P3HIGHCVSS 7.0fixed in 10.0.26100.83902026-05-12
CVE-2026-35416 [HIGH] CWE-416 CVE-2026-35416: Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver f
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-29842P3HIGHCVSS 7.5fixed in 10.0.26100.40612025-05-13
CVE-2025-29842 [HIGH] CWE-349 CVE-2025-29842: Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker
Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2025-54919P3HIGHCVSS 7.5fixed in 10.0.26100.65082025-09-09
CVE-2025-54919 [HIGH] CWE-362 CVE-2025-54919: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
nvd
CVE-2026-27908P3HIGHCVSS 7.0fixed in 10.0.26100.82462026-04-14
CVE-2026-27908 [HIGH] CWE-416 CVE-2026-27908: Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate
Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49690P3HIGHCVSS 7.4fixed in 10.0.26100.46522025-07-08
CVE-2025-49690 [HIGH] CWE-362 CVE-2025-49690: Concurrent execution using shared resource with improper synchronization ('race condition') in Capab
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2025-25004P3HIGHCVSS 7.3fixed in 10.0.26100.68992025-10-14
CVE-2025-25004 [HIGH] CWE-284 CVE-2025-25004: Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges
Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-27921P3HIGHCVSS 7.0fixed in 10.0.26100.82462026-04-14
CVE-2026-27921 [HIGH] CWE-362 CVE-2026-27921: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50682P3HIGHCVSS 7.1fixed in 10.0.26100.88752026-07-14
CVE-2026-50682 [HIGH] CWE-125 CVE-2026-50682: Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a
Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.
nvd
CVE-2026-41108P3HIGHCVSS 7.0fixed in 10.0.26100.86552026-06-09
CVE-2026-41108 [HIGH] CWE-122 CVE-2026-41108: Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privile
Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-45653P3HIGHCVSS 7.0fixed in 10.0.26100.86552026-06-09
CVE-2026-45653 [HIGH] CWE-122 CVE-2026-45653: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-30073P3HIGHCVSS 7.8fixed in 10.0.26100.17422024-09-10
CVE-2024-30073 [HIGH] CWE-41 CVE-2024-30073: Windows Security Zone Mapping Security Feature Bypass Vulnerability
Windows Security Zone Mapping Security Feature Bypass Vulnerability
nvd
CVE-2025-21373P3HIGHCVSS 7.8fixed in 10.0.26100.31942025-02-11
CVE-2025-21373 [HIGH] CWE-59 CVE-2025-21373: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2024-43641P3HIGHCVSS 7.8fixed in 10.0.26100.23142024-11-12
CVE-2024-43641 [HIGH] CWE-190 CVE-2024-43641: Windows Registry Elevation of Privilege Vulnerability
Windows Registry Elevation of Privilege Vulnerability
nvd
CVE-2024-43551P3HIGHCVSS 7.8fixed in 10.0.26100.20332024-10-08
CVE-2024-43551 [HIGH] CWE-59 CVE-2024-43551: Windows Storage Elevation of Privilege Vulnerability
Windows Storage Elevation of Privilege Vulnerability
nvd
CVE-2024-43457P3HIGHCVSS 7.8fixed in 10.0.26100.17422024-09-10
CVE-2024-43457 [HIGH] CWE-428 CVE-2024-43457: Windows Setup and Deployment Elevation of Privilege Vulnerability
Windows Setup and Deployment Elevation of Privilege Vulnerability
nvd
CVE-2024-49072P3HIGHCVSS 7.8fixed in 10.0.26100.26052024-12-12
CVE-2024-49072 [HIGH] CWE-122 CVE-2024-49072: Windows Task Scheduler Elevation of Privilege Vulnerability
Windows Task Scheduler Elevation of Privilege Vulnerability
nvd
CVE-2025-21275P3HIGHCVSS 7.8fixed in 10.0.26100.28942025-01-14
CVE-2025-21275 [HIGH] CWE-285 CVE-2025-21275: Windows App Package Installer Elevation of Privilege Vulnerability
Windows App Package Installer Elevation of Privilege Vulnerability
nvd
CVE-2024-49107P3HIGHCVSS 7.3fixed in 10.0.26100.26052024-12-12
CVE-2024-49107 [HIGH] CWE-59 CVE-2024-49107: WmsRepair Service Elevation of Privilege Vulnerability
WmsRepair Service Elevation of Privilege Vulnerability
nvd
CVE-2025-21281P3HIGHCVSS 7.8fixed in 10.0.26100.28942025-01-14
CVE-2025-21281 [HIGH] CWE-416 CVE-2025-21281: Microsoft COM for Windows Elevation of Privilege Vulnerability
Microsoft COM for Windows Elevation of Privilege Vulnerability
nvd
CVE-2025-21234P3HIGHCVSS 7.8fixed in 10.0.26100.28942025-01-14
CVE-2025-21234 [HIGH] CWE-20 CVE-2025-21234: Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
nvd