Msrc Windows 11 Version 24H2 vulnerabilities
845 known vulnerabilities affecting msrc/windows_11_version_24h2.
Total CVEs
845
CISA KEV
40
actively exploited
Public exploits
17
Exploited in wild
14
Severity breakdown
CRITICAL11HIGH588MEDIUM241LOW5
Vulnerabilities
Page 24 of 43
CVE-2025-29836MEDIUMCVSS 6.52025-05-13
CVE-2025-29836 [MEDIUM] CWE-125 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
FAQ: According to the CVSS metric, user interaction is required (UI:R) and privileges required are none (PR:N). What does that mean for th
msrc
CVE-2025-29961MEDIUMCVSS 6.52025-05-13
CVE-2025-29961 [MEDIUM] CWE-125 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
In a web-based attack
msrc
CVE-2025-29830MEDIUMCVSS 6.52025-05-13
CVE-2025-29830 [MEDIUM] CWE-908 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Description: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerabili
msrc
CVE-2025-29832MEDIUMCVSS 6.52025-05-13
CVE-2025-29832 [MEDIUM] CWE-125 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could po
msrc
CVE-2025-29956MEDIUMCVSS 5.42025-05-13
CVE-2025-29956 [MEDIUM] CWE-126 Windows SMB Information Disclosure Vulnerability
Windows SMB Information Disclosure Vulnerability
Description: Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network.
FAQ: According to the CVSS metric, user interaction is required (UI:R) and privileges required is low (PR:L). What does that mean for this vulnerability?
The attack requires to trick a user to open an SMB share folder that is hosted on the attacker-cont
msrc
CVE-2025-29958MEDIUMCVSS 6.52025-05-13
CVE-2025-29958 [MEDIUM] CWE-908 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Description: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerabili
msrc
CVE-2025-29957MEDIUMCVSS 6.22025-05-13
CVE-2025-29957 [MEDIUM] CWE-400 Windows Deployment Services Denial of Service Vulnerability
Windows Deployment Services Denial of Service Vulnerability
Description: Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally.
Windows Deployment Services: Windows Deployment Services
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Releas
msrc
CVE-2025-29835MEDIUMCVSS 6.52025-05-13
CVE-2025-29835 [MEDIUM] CWE-125 Windows Remote Access Connection Manager Information Disclosure Vulnerability
Windows Remote Access Connection Manager Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read p
msrc
CVE-2025-29959MEDIUMCVSS 6.52025-05-13
CVE-2025-29959 [MEDIUM] CWE-908 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Description: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerabili
msrc
CVE-2025-29839MEDIUMCVSS 4.02025-05-13
CVE-2025-29839 [MEDIUM] CWE-125 Windows Multiple UNC Provider Driver Information Disclosure Vulnerability
Windows Multiple UNC Provider Driver Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L),but lead to no loss of availability (A:N) and integrity (I:N)? What
msrc
CVE-2025-27491HIGHCVSS 7.12025-04-08
CVE-2025-27491 [HIGH] CWE-416 Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability
Description: Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condition.
FAQ: Are the updates for Windows 10 for x64-b
msrc
CVE-2025-26663HIGHCVSS 8.12025-04-08
CVE-2025-26663 [HIGH] CWE-416 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Description: Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation o
msrc
CVE-2025-27481HIGHCVSS 8.82025-04-08
CVE-2025-27481 [HIGH] CWE-121 Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
Description: Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
FAQ: According to the CVSS metric, the attack vector is network (AV:N) and the user interaction is required (UI:R). What is the target context of the remote code execution?
This attack requires a client to conn
msrc
CVE-2025-21222HIGHCVSS 8.82025-04-08
CVE-2025-21222 [HIGH] CWE-122 Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
Description: Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
FAQ: Are the updates for Windows 10 for x64-based Systems and Windows 10 for 32-bit Systems currently available?
Yes. As of April 9, 2025, the security update (5055547) for Windows 10 for x64-based Systems and W
msrc
CVE-2025-26679HIGHCVSS 7.82025-04-08
CVE-2025-26679 [HIGH] CWE-416 RPC Endpoint Mapper Service Elevation of Privilege Vulnerability
RPC Endpoint Mapper Service Elevation of Privilege Vulnerability
Description: Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker who successfully exploited this vulnerability could execute code in the security context of the “NT AUTHORIT
msrc
CVE-2025-27477HIGHCVSS 8.82025-04-08
CVE-2025-27477 [HIGH] CWE-122 Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
Description: Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
FAQ: How could an attacker exploit this vulnerability?
An attacker could exploit this vulnerability by tricking a user into sending a request to a malicious server. This could result in the server returning mali
msrc
CVE-2025-26665HIGHCVSS 7.02025-04-08
CVE-2025-26665 [HIGH] CWE-591 Windows upnphost.dll Elevation of Privilege Vulnerability
Windows upnphost.dll Elevation of Privilege Vulnerability
Description: Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate privileges locally.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condi
msrc
CVE-2025-21204HIGHCVSS 7.82025-04-08
CVE-2025-21204 [HIGH] CWE-59 Windows Process Activation Elevation of Privilege Vulnerability
Windows Process Activation Elevation of Privilege Vulnerability
Description: Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
FAQ: Are the updates for Windows 10 for x64-based Systems and Windows 10 for 32-bit Systems currently available?
Yes. As of April 9, 2025, the security update (5055547) for Windows
msrc
CVE-2025-26668HIGHCVSS 7.52025-04-08
CVE-2025-26668 [HIGH] CWE-122 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Description: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
FAQ: According to the CVSS metric, the attack vector is network (AV:N) and the user interaction is required (UI:R). What is the target context
msrc
CVE-2025-29824HIGHCVSS 7.8KEV2025-04-08
CVE-2025-29824 [HIGH] CWE-416 Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Description: Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
FAQ: Are the updates for Windows 10 for x64-based Systems and Windows 10 for 32-bit Systems currently available?
Yes. As of April 9, 2025, the security update (5055547) for Windows 10 for
msrc