Msrc Windows 11 Version 24H2 vulnerabilities
845 known vulnerabilities affecting msrc/windows_11_version_24h2.
Total CVEs
845
CISA KEV
40
actively exploited
Public exploits
17
Exploited in wild
14
Severity breakdown
CRITICAL11HIGH588MEDIUM241LOW5
Vulnerabilities
Page 22 of 43
CVE-2025-24069MEDIUMCVSS 5.52025-06-10
CVE-2025-24069 [MEDIUM] CWE-125 Windows Storage Management Provider Information Disclosure Vulnerability
Windows Storage Management Provider Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
W
msrc
CVE-2025-33060MEDIUMCVSS 5.52025-06-10
CVE-2025-33060 [MEDIUM] CWE-125 Windows Storage Management Provider Information Disclosure Vulnerability
Windows Storage Management Provider Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
W
msrc
CVE-2025-32719MEDIUMCVSS 5.52025-06-10
CVE-2025-32719 [MEDIUM] CWE-125 Windows Storage Management Provider Information Disclosure Vulnerability
Windows Storage Management Provider Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
W
msrc
CVE-2025-24068MEDIUMCVSS 5.52025-06-10
CVE-2025-24068 [MEDIUM] CWE-126 Windows Storage Management Provider Information Disclosure Vulnerability
Windows Storage Management Provider Information Disclosure Vulnerability
Description: Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
Win
msrc
CVE-2025-33055MEDIUMCVSS 5.52025-06-10
CVE-2025-33055 [MEDIUM] CWE-125 Windows Storage Management Provider Information Disclosure Vulnerability
Windows Storage Management Provider Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
W
msrc
CVE-2025-24065MEDIUMCVSS 5.52025-06-10
CVE-2025-24065 [MEDIUM] CWE-125 Windows Storage Management Provider Information Disclosure Vulnerability
Windows Storage Management Provider Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is an out
msrc
CVE-2025-32722MEDIUMCVSS 5.52025-06-10
CVE-2025-32722 [MEDIUM] CWE-284 Windows Storage Port Driver Information Disclosure Vulnerability
Windows Storage Port Driver Information Disclosure Vulnerability
Description: Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
Exploiting this vulnerability could allow the disclosure of certain memory address within kernel space. Knowing the exact location of
msrc
CVE-2025-33058MEDIUMCVSS 5.52025-06-10
CVE-2025-33058 [MEDIUM] CWE-125 Windows Storage Management Provider Information Disclosure Vulnerability
Windows Storage Management Provider Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
W
msrc
CVE-2025-33057MEDIUMCVSS 6.52025-06-10
CVE-2025-33057 [MEDIUM] CWE-476 Windows Local Security Authority (LSA) Denial of Service Vulnerability
Windows Local Security Authority (LSA) Denial of Service Vulnerability
Description: Null pointer dereference in Windows Local Security Authority (LSA) allows an authorized attacker to deny service over a network.
Windows Local Security Authority (LSA): Windows Local Security Authority (LSA)
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Public
msrc
CVE-2025-33052MEDIUMCVSS 5.52025-06-10
CVE-2025-33052 [MEDIUM] CWE-908 Windows DWM Core Library Information Disclosure Vulnerability
Windows DWM Core Library Information Disclosure Vulnerability
Description: Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized stack memory.
msrc
CVE-2025-33063MEDIUMCVSS 5.52025-06-10
CVE-2025-33063 [MEDIUM] CWE-125 Windows Storage Management Provider Information Disclosure Vulnerability
Windows Storage Management Provider Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
W
msrc
CVE-2025-3052MEDIUMCVSS 6.72025-06-10
CVE-2025-3052 [HIGH] CWE-822 Cert CC: CVE-2025-3052 InsydeH2O Secure Boot Bypass
Cert CC: CVE-2025-3052 InsydeH2O Secure Boot Bypass
Description: Untrusted pointer dereference in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could bypass Secure Boot.
FAQ: Why is this CERT/CC CVE included in the S
msrc
CVE-2025-32720MEDIUMCVSS 5.52025-06-10
CVE-2025-32720 [MEDIUM] CWE-125 Windows Storage Management Provider Information Disclosure Vulnerability
Windows Storage Management Provider Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
W
msrc
CVE-2025-33061MEDIUMCVSS 5.52025-06-10
CVE-2025-33061 [MEDIUM] CWE-125 Windows Storage Management Provider Information Disclosure Vulnerability
Windows Storage Management Provider Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
W
msrc
CVE-2025-33065MEDIUMCVSS 5.52025-06-10
CVE-2025-33065 [MEDIUM] CWE-125 Windows Storage Management Provider Information Disclosure Vulnerability
Windows Storage Management Provider Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
W
msrc
CVE-2025-33059MEDIUMCVSS 5.52025-06-10
CVE-2025-33059 [MEDIUM] CWE-125 Windows Storage Management Provider Information Disclosure Vulnerability
Windows Storage Management Provider Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
W
msrc
CVE-2025-47160MEDIUMCVSS 5.42025-06-10
CVE-2025-47160 [MEDIUM] CWE-693 Windows Shortcut Files Security Feature Bypass Vulnerability
Windows Shortcut Files Security Feature Bypass Vulnerability
Description: Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to no loss of confidentiality (C:N), but could lead to some loss of integrity (I:L) and availability (A:L). What do
msrc
CVE-2025-32715MEDIUMCVSS 6.52025-06-10
CVE-2025-32715 [MEDIUM] CWE-125 Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability
Description: Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
FAQ: According t
msrc
CVE-2025-33062MEDIUMCVSS 5.52025-06-10
CVE-2025-33062 [MEDIUM] CWE-125 Windows Storage Management Provider Information Disclosure Vulnerability
Windows Storage Management Provider Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
W
msrc
CVE-2025-29833HIGHCVSS 7.72025-05-13
CVE-2025-29833 [HIGH] CWE-367 Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
Description: Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to execute code locally.
FAQ: According to the CVSS metric, user interaction is required (UI:R) and privileges required is Low (PR:L). What does that mean for this vulnerability?
An authorized a
msrc