Microsoft Windows 11 Version 24H2 vulnerabilities
1,731 known vulnerabilities affecting microsoft/windows_11_version_24h2.
Total CVEs
1,731
CISA KEV
44
actively exploited
Public exploits
32
Exploited in wild
52
Severity breakdown
CRITICAL39HIGH1236MEDIUM447LOW9
Vulnerabilities
Page 5 of 87
CVE-2025-53143P2HIGHCVSS 8.8≥ 10.0.26100.0, < 10.0.26100.49462025-08-12
CVE-2025-53143 [HIGH] CWE-843 CVE-2025-53143: Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an a
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
nvd
CVE-2025-53145P2HIGHCVSS 8.8≥ 10.0.26100.0, < 10.0.26100.49462025-08-12
CVE-2025-53145 [HIGH] CWE-843 CVE-2025-53145: Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an a
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
nvd
CVE-2025-50165P2CRITICALCVSS 9.8≥ 10.0.26100.0, < 10.0.26100.49462025-08-12
CVE-2025-50165 [CRITICAL] CWE-822 CVE-2025-50165: Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to exe
Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-53144P2HIGHCVSS 8.8≥ 10.0.26100.0, < 10.0.26100.49462025-08-12
CVE-2025-53144 [HIGH] CWE-843 CVE-2025-53144: Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an a
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
nvd
CVE-2024-38140P2CRITICALCVSS 9.8≥ 10.0.26100.0, < 10.0.26100.14572024-08-13
CVE-2024-38140 [CRITICAL] CWE-416 CVE-2024-38140: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
nvd
CVE-2024-43532P2HIGHCVSS 8.8≥ 10.0.26100.0, < 10.0.26100.20332024-10-08
CVE-2024-43532 [HIGH] CWE-636 CVE-2024-43532: Remote Registry Service Elevation of Privilege Vulnerability
Remote Registry Service Elevation of Privilege Vulnerability
nvd
CVE-2024-21416P2CRITICALCVSS 9.8≥ 10.0.26100.0, < 10.0.26100.17422024-09-10
CVE-2024-21416 [CRITICAL] CWE-122 CVE-2024-21416: Windows TCP/IP Remote Code Execution Vulnerability
Windows TCP/IP Remote Code Execution Vulnerability
nvd
CVE-2025-29962P2HIGHCVSS 8.8≥ 10.0.26100.0, < 10.0.26100.40612025-05-13
CVE-2025-29962 [HIGH] CWE-122 CVE-2025-29962: Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a n
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-50439P2CRITICALCVSS 9.8≥ 10.0.26100.0, < 10.0.26100.88752026-07-14
CVE-2026-50439 [CRITICAL] CWE-416 CVE-2026-50439: Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute
Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21369P2HIGHCVSS 8.8≥ 10.0.26100.0, < 10.0.26100.31942025-02-11
CVE-2025-21369 [HIGH] CWE-122 CVE-2025-21369: Microsoft Digest Authentication Remote Code Execution Vulnerability
Microsoft Digest Authentication Remote Code Execution Vulnerability
nvd
CVE-2025-21368P2HIGHCVSS 8.8≥ 10.0.26100.0, < 10.0.26100.31942025-02-11
CVE-2025-21368 [HIGH] CWE-122 CVE-2025-21368: Microsoft Digest Authentication Remote Code Execution Vulnerability
Microsoft Digest Authentication Remote Code Execution Vulnerability
nvd
CVE-2025-49744P3HIGHCVSS 7.0PoC≥ 10.0.26100.0, < 10.0.26100.46522025-07-08
CVE-2025-49744 [HIGH] CWE-122 CVE-2025-49744: Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56194P2HIGHCVSS 8.8≥ 10.0.26100.0, < 10.0.26100.88752026-07-14
CVE-2026-56194 [HIGH] CWE-122 CVE-2026-56194: Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate p
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-56647P2HIGHCVSS 8.8≥ 10.0.26100.0, < 10.0.26100.88752026-07-14
CVE-2026-56647 [HIGH] CWE-190 CVE-2026-56647: Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized
Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2024-38199P2CRITICALCVSS 9.8≥ 10.0.26100.0, < 10.0.26100.14572024-08-13
CVE-2024-38199 [CRITICAL] CWE-416 CVE-2024-38199: Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
nvd
CVE-2025-21307P2CRITICALCVSS 9.8≥ 10.0.26100.0, < 10.0.26100.28942025-01-14
CVE-2025-21307 [CRITICAL] CWE-416 CVE-2025-21307: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
nvd
CVE-2026-57092P2CRITICALCVSS 9.9≥ 10.0.26100.0, < 10.0.26100.88752026-07-14
CVE-2026-57092 [CRITICAL] CWE-416 CVE-2026-57092: Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a networ
Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-57090P2CRITICALCVSS 9.8≥ 10.0.26100.0, < 10.0.26100.88752026-07-14
CVE-2026-57090 [CRITICAL] CWE-122 CVE-2026-57090: Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-49172P2CRITICALCVSS 9.8≥ 10.0.26100.0, < 10.0.26100.88752026-07-14
CVE-2026-49172 [CRITICAL] CWE-122 CVE-2026-49172: Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code ov
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-54995P2CRITICALCVSS 9.8≥ 10.0.26100.0, < 10.0.26100.88752026-07-14
CVE-2026-54995 [CRITICAL] CWE-416 CVE-2026-54995: Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to ex
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
nvd