cbcvebase.

Microsoft Windows 11 24H2 vulnerabilities

1,692 known vulnerabilities affecting microsoft/windows_11_24h2.

Total CVEs
1,692
CISA KEV
40
actively exploited
Public exploits
29
Exploited in wild
47
Severity breakdown
CRITICAL37HIGH1215MEDIUM432LOW8

Vulnerabilities

Page 83 of 85
CVE-2026-45606P4MEDIUMCVSS 5.5fixed in 10.0.26100.86552026-06-09
CVE-2026-45606 [MEDIUM] CWE-125 CVE-2026-45606: Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.
nvd
CVE-2025-48813P4MEDIUMCVSS 4.7fixed in 10.0.26100.68992025-10-14
CVE-2025-48813 [MEDIUM] CWE-324 CVE-2025-48813: Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perfor Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.
nvd
CVE-2026-20962P4MEDIUMCVSS 4.4fixed in 10.0.26100.76232026-01-13
CVE-2026-20962 [MEDIUM] CWE-908 CVE-2026-20962: Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized a Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally.
nvd
CVE-2026-27906P4MEDIUMCVSS 4.4fixed in 10.0.26100.82462026-04-14
CVE-2026-27906 [MEDIUM] CWE-20 CVE-2026-27906: Improper input validation in Windows Hello allows an authorized attacker to bypass a security featur Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-32220P4MEDIUMCVSS 4.4fixed in 10.0.26100.82462026-04-14
CVE-2026-32220 [MEDIUM] CWE-284 CVE-2026-32220: Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-32209P4MEDIUMCVSS 4.4fixed in 10.0.26100.83902026-05-12
CVE-2026-32209 [MEDIUM] CWE-284 CVE-2026-32209: Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2024-38234P4MEDIUMCVSS 6.5fixed in 10.0.26100.17422024-09-10
CVE-2024-38234 [MEDIUM] CWE-20 CVE-2024-38234: Windows Networking Denial of Service Vulnerability Windows Networking Denial of Service Vulnerability
nvd
CVE-2024-43555P4MEDIUMCVSS 6.5fixed in 10.0.26100.20332024-10-08
CVE-2024-43555 [MEDIUM] CWE-125 CVE-2024-43555: Windows Mobile Broadband Driver Denial of Service Vulnerability Windows Mobile Broadband Driver Denial of Service Vulnerability
nvd
CVE-2024-43561P4MEDIUMCVSS 6.5fixed in 10.0.26100.20332024-10-08
CVE-2024-43561 [MEDIUM] CWE-20 CVE-2024-43561: Windows Mobile Broadband Driver Denial of Service Vulnerability Windows Mobile Broadband Driver Denial of Service Vulnerability
nvd
CVE-2024-43558P4MEDIUMCVSS 6.5fixed in 10.0.26100.20332024-10-08
CVE-2024-43558 [MEDIUM] CWE-20 CVE-2024-43558: Windows Mobile Broadband Driver Denial of Service Vulnerability Windows Mobile Broadband Driver Denial of Service Vulnerability
nvd
CVE-2024-43557P4MEDIUMCVSS 6.5fixed in 10.0.26100.20332024-10-08
CVE-2024-43557 [MEDIUM] CWE-20 CVE-2024-43557: Windows Mobile Broadband Driver Denial of Service Vulnerability Windows Mobile Broadband Driver Denial of Service Vulnerability
nvd
CVE-2024-43559P4MEDIUMCVSS 6.5fixed in 10.0.26100.20332024-10-08
CVE-2024-43559 [MEDIUM] CWE-476 CVE-2024-43559: Windows Mobile Broadband Driver Denial of Service Vulnerability Windows Mobile Broadband Driver Denial of Service Vulnerability
nvd
CVE-2024-43538P4MEDIUMCVSS 6.5fixed in 10.0.26100.20332024-10-08
CVE-2024-43538 [MEDIUM] CWE-20 CVE-2024-43538: Windows Mobile Broadband Driver Denial of Service Vulnerability Windows Mobile Broadband Driver Denial of Service Vulnerability
nvd
CVE-2024-43542P4MEDIUMCVSS 6.5fixed in 10.0.26100.20332024-10-08
CVE-2024-43542 [MEDIUM] CWE-20 CVE-2024-43542: Windows Mobile Broadband Driver Denial of Service Vulnerability Windows Mobile Broadband Driver Denial of Service Vulnerability
nvd
CVE-2024-43537P4MEDIUMCVSS 6.5fixed in 10.0.17763.64142024-10-08
CVE-2024-43537 [MEDIUM] CWE-125 CVE-2024-43537: Windows Mobile Broadband Driver Denial of Service Vulnerability Windows Mobile Broadband Driver Denial of Service Vulnerability
nvd
CVE-2024-43540P4MEDIUMCVSS 6.5fixed in 10.0.26100.20332024-10-08
CVE-2024-43540 [MEDIUM] CWE-20 CVE-2024-43540: Windows Mobile Broadband Driver Denial of Service Vulnerability Windows Mobile Broadband Driver Denial of Service Vulnerability
nvd
CVE-2025-21347P4MEDIUMCVSS 6.0fixed in 10.0.26100.31942025-02-11
CVE-2025-21347 [MEDIUM] CWE-59 CVE-2025-21347: Windows Deployment Services Denial of Service Vulnerability Windows Deployment Services Denial of Service Vulnerability
nvd
CVE-2024-38151P4MEDIUMCVSS 5.5fixed in 10.0.26100.14572024-08-13
CVE-2024-38151 [MEDIUM] CWE-125 CVE-2024-38151: Windows Kernel Information Disclosure Vulnerability Windows Kernel Information Disclosure Vulnerability
nvd
CVE-2024-43508P4MEDIUMCVSS 5.5fixed in 10.0.26100.20332024-10-08
CVE-2024-43508 [MEDIUM] CWE-125 CVE-2024-43508: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2025-21374P4MEDIUMCVSS 5.5fixed in 10.0.26100.28942025-01-14
CVE-2025-21374 [MEDIUM] CWE-125 CVE-2025-21374: Windows CSC Service Information Disclosure Vulnerability Windows CSC Service Information Disclosure Vulnerability
nvd
Microsoft Windows 11 24H2 vulnerabilities | cvebase