Microsoft Windows 11 Version 23H2 vulnerabilities

1,506 known vulnerabilities affecting microsoft/windows_11_version_23h2.

Total CVEs
1,506
CISA KEV
58
actively exploited
Public exploits
24
Exploited in wild
30
Severity breakdown
CRITICAL18HIGH1051MEDIUM430LOW7

Vulnerabilities

Page 76 of 76
CVE-2023-36406MEDIUMCVSS 5.5≥ 10.0.22631.0, < 10.0.22631.27152023-11-14
CVE-2023-36406 [MEDIUM] CWE-20 CVE-2023-36406: Windows Hyper-V Information Disclosure Vulnerability Windows Hyper-V Information Disclosure Vulnerability
nvd
CVE-2023-36404MEDIUMCVSS 5.5≥ 10.0.22631.0, < 10.0.22631.27152023-11-14
CVE-2023-36404 [MEDIUM] CWE-284 CVE-2023-36404: Windows Kernel Information Disclosure Vulnerability Windows Kernel Information Disclosure Vulnerability
nvd
CVE-2023-36428MEDIUMCVSS 5.5≥ 10.0.22631.0, < 10.0.22631.27152023-11-14
CVE-2023-36428 [MEDIUM] CWE-125 CVE-2023-36428: Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
nvd
CVE-2023-36398MEDIUMCVSS 6.5≥ 10.0.22631.0, < 10.0.22631.27152023-11-14
CVE-2023-36398 [MEDIUM] CWE-908 Windows NTFS Information Disclosure Vulnerability Windows NTFS Information Disclosure Vulnerability Windows NTFS Information Disclosure Vulnerability
cvelistv5
CVE-2023-24932MEDIUMCVSS 6.7Exploited≥ 10.0.22631.0, < 10.0.22631.56242023-05-09
CVE-2023-24932 [MEDIUM] Secure Boot Security Feature Bypass Vulnerability Secure Boot Security Feature Bypass Vulnerability Secure Boot Security Feature Bypass Vulnerability
cvelistv5
CVE-2013-3900HIGHCVSS 8.8KEVvN/A2013-12-11
CVE-2013-3900 [HIGH] CWE-347 CVE-2013-3900: Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Upd Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in all currently supported versions of Windows 10 and Windows 11. While the format is different from the original CVE published in 2013, ex
nvd