cbcvebase.

Microsoft Windows 11 Version 23H2 vulnerabilities

1,661 known vulnerabilities affecting microsoft/windows_11_version_23h2.

Total CVEs
1,661
CISA KEV
59
actively exploited
Public exploits
42
Exploited in wild
71
Severity breakdown
CRITICAL25HIGH1170MEDIUM458LOW8

Vulnerabilities

Page 46 of 84
CVE-2024-30031P3HIGHCVSS 7.8≥ 10.0.22631.0, < 10.0.22631.35932024-05-14
CVE-2024-30031 [HIGH] CWE-416 CVE-2024-30031: Windows CNG Key Isolation Service Elevation of Privilege Vulnerability Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
nvd
CVE-2026-20816P3HIGHCVSS 7.0≥ 10.0.22631.0, < 10.0.22631.64912026-01-13
CVE-2026-20816 [HIGH] CWE-367 CVE-2026-20816: Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-58720P3HIGHCVSS 7.8≥ 10.0.22631.0, < 10.0.22631.60602025-10-14
CVE-2025-58720 [HIGH] CWE-1240 CVE-2025-58720: Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allow Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally.
nvd
CVE-2025-29833P3HIGHCVSS 7.7≥ 10.0.22631.0, < 10.0.22631.53352025-05-13
CVE-2025-29833 [HIGH] CWE-367 CVE-2025-29833: Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthori Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-24994P3HIGHCVSS 7.3≥ 10.0.22631.0, < 10.0.22631.50392025-03-11
CVE-2025-24994 [HIGH] CWE-284 CVE-2025-24994: Improper access control in Windows Cross Device Service allows an authorized attacker to elevate pri Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-43495P3HIGHCVSS 7.3≥ 10.0.22631.0, < 10.0.22621.38802024-09-10
CVE-2024-43495 [HIGH] CWE-190 CVE-2024-43495: Windows libarchive Remote Code Execution Vulnerability Windows libarchive Remote Code Execution Vulnerability
nvd
CVE-2025-60719P3HIGHCVSS 7.0≥ 10.0.22631.0, < 10.0.22631.61992025-11-11
CVE-2025-60719 [HIGH] CWE-822 CVE-2025-60719: Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-62213P3HIGHCVSS 7.0≥ 10.0.22631.0, < 10.0.22631.61992025-11-11
CVE-2025-62213 [HIGH] CWE-416 CVE-2025-62213: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-21197P3MEDIUMCVSS 6.5≥ 10.0.22631.0, < 10.0.22631.51892025-04-08
CVE-2025-21197 [MEDIUM] CWE-284 CVE-2025-21197: Improper access control in Windows NTFS allows an authorized attacker to disclose file path informat Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content.
nvd
CVE-2025-49682P3HIGHCVSS 7.3≥ 10.0.22631.0, < 10.0.22631.56242025-07-08
CVE-2025-49682 [HIGH] CWE-416 CVE-2025-49682: Use after free in Windows Media allows an authorized attacker to elevate privileges locally. Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49727P3HIGHCVSS 7.0≥ 10.0.22631.0, < 10.0.22631.56242025-07-08
CVE-2025-49727 [HIGH] CWE-122 CVE-2025-49727: Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privile Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-41108P3HIGHCVSS 7.0≥ 10.0.22631.0, < 10.0.22631.72192026-06-09
CVE-2026-41108 [HIGH] CWE-122 CVE-2026-41108: Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privile Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-58725P3HIGHCVSS 7.0≥ 10.0.22631.0, < 10.0.22631.60602025-10-14
CVE-2025-58725 [HIGH] CWE-122 CVE-2025-58725: Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locall Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20876P3MEDIUMCVSS 6.7≥ 10.0.22631.0, < 10.0.22631.64912026-01-13
CVE-2026-20876 [MEDIUM] CWE-122 CVE-2026-20876: Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authoriz Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-26254P3HIGHCVSS 7.5≥ 10.0.22631.0, < 10.0.22631.34472024-04-09
CVE-2024-26254 [HIGH] CWE-822 CVE-2024-26254: Microsoft Virtual Machine Bus (VMBus) Denial of Service Vulnerability Microsoft Virtual Machine Bus (VMBus) Denial of Service Vulnerability
nvd
CVE-2023-36399P3HIGHCVSS 7.1≥ 10.0.22631.0, < 10.0.22631.27152023-11-14
CVE-2023-36399 [HIGH] CWE-59 CVE-2023-36399: Windows Storage Elevation of Privilege Vulnerability Windows Storage Elevation of Privilege Vulnerability
nvd
CVE-2024-26232P3HIGHCVSS 7.3≥ 10.0.22631.0, < 10.0.22631.34472024-04-09
CVE-2024-26232 [HIGH] CWE-843 CVE-2024-26232: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2025-27491P3HIGHCVSS 7.1≥ 10.0.22631.0, < 10.0.22631.51892025-04-08
CVE-2025-27491 [HIGH] CWE-416 CVE-2025-27491: Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network. Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network.
nvd
CVE-2026-40414P3HIGHCVSS 7.4≥ 10.0.22631.0, < 10.0.22631.70792026-05-12
CVE-2026-40414 [HIGH] CWE-476 CVE-2026-40414: Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an a Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an adjacent network.
cvelistv5nvd
CVE-2025-32721P3HIGHCVSS 7.3≥ 10.0.22631.0, < 10.0.22631.54722025-06-10
CVE-2025-32721 [HIGH] CWE-59 CVE-2025-32721: Improper link resolution before file access ('link following') in Windows Recovery Driver allows an Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows 11 Version 23H2 vulnerabilities | cvebase