microsoft / windows_11_23h2
761 known vulnerabilities in microsoft windows_11_23h2.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-77495 | Medium | 0.6% | 8.8 | Heap-based buffer overflow in Windows Imaging Component allows an unauthorized a… | |
| CVE-2026-48563 | Medium | 0.6% | 7.5 | Use after free in Remote Desktop Client allows an unauthorized attacker to execu… | |
| CVE-2026-62706 | Medium | 0.5% | 8.8 | Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized … | |
| CVE-2026-62872 | Medium | 0.5% | 8.8 | Incorrect authorization in .NET Framework allows an authorized attacker to eleva… | |
| CVE-2026-69314 | Medium | 0.5% | 7.1 | Use after free in Windows Device Association Broker service allows an authorized… | |
| CVE-2026-44803 | Medium | 0.5% | 7.8 | Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized a… | |
| CVE-2026-44812 | Medium | 0.5% | 7.8 | Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized a… | |
| CVE-2026-68835 | Medium | 0.5% | 7.1 | Use after free in Windows Print Spooler Components allows an authorized attacker… | |
| CVE-2026-69340 | Medium | 0.5% | 7.1 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elev… | |
| CVE-2026-45599 | Medium | 0.5% | 8.1 | Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized atta… | |
| CVE-2026-45635 | Medium | 0.5% | 8.1 | Access of resource using incompatible type ('type confusion') in Universal Plug … | |
| CVE-2026-62781 | Medium | 0.5% | 8.1 | Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to exe… | |
| CVE-2026-69539 | Medium | 0.5% | 7.5 | Use after free in Windows Remote Desktop Services allows an authorized attacker … | |
| CVE-2026-20804 | Medium | 0.5% | 7.7 | Incorrect privilege assignment in Windows Hello allows an unauthorized attacker … | |
| CVE-2026-20852 | Medium | 0.5% | 7.7 | Incorrect privilege assignment in Windows Hello allows an unauthorized attacker … | |
| CVE-2026-83997 | Medium | 0.5% | 8.1 | Use after free in Windows Message Queuing allows an unauthorized attacker to exe… | |
| CVE-2026-20920 | Medium | 0.5% | 7.8 | Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevat… | |
| CVE-2026-20811 | Medium | 0.5% | 7.8 | Access of resource using incompatible type ('type confusion') in Windows Win32K … | |
| CVE-2026-69847 | Medium | 0.5% | 8.0 | Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker … | |
| CVE-2026-20832 | Medium | 0.5% | 7.8 | Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of P… | |
| CVE-2026-20857 | Medium | 0.5% | 7.8 | Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows a… | |
| CVE-2026-62735 | Medium | 0.5% | 7.8 | Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to … | |
| CVE-2026-20938 | Medium | 0.5% | 7.8 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enc… | |
| CVE-2026-42913 | Medium | 0.5% | 7.5 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50471 | Medium | 0.5% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to ex… | |
| CVE-2026-20940 | Medium | 0.5% | 7.8 | Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an a… | |
| CVE-2026-42992 | Medium | 0.5% | 7.5 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac… | |
| CVE-2026-44799 | Medium | 0.5% | 7.5 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac… | |
| CVE-2026-44801 | Medium | 0.5% | 7.5 | Use after free in Remote Desktop Client allows an unauthorized attacker to execu… | |
| CVE-2026-48574 | Medium | 0.4% | 7.8 | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to e… | |
| CVE-2026-69536 | Medium | 0.4% | 7.1 | Use after free in Windows Remote Desktop Services allows an authorized attacker … | |
| CVE-2026-42904 | Medium | 0.4% | 9.6 | Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to … | |
| CVE-2026-42993 | Medium | 0.4% | 7.5 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac… | |
| CVE-2026-61352 | Medium | 0.4% | 7.5 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-45636 | Medium | 0.4% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to ex… | |
| CVE-2026-20923 | Medium | 0.4% | 7.8 | Use after free in Windows Management Services allows an authorized attacker to e… | |
| CVE-2026-62721 | Medium | 0.4% | 7.8 | Insufficient granularity of access control in User-Mode Power Service (UMPS) all… | |
| CVE-2026-68827 | Medium | 0.4% | 8.0 | Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized atta… | |
| CVE-2026-68838 | Medium | 0.4% | 8.0 | Stack-based buffer overflow in Windows NTFS allows an authorized attacker to ele… | |
| CVE-2026-42909 | Medium | 0.4% | 7.5 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20822 | Medium | 0.4% | 7.8 | Use after free in Microsoft Graphics Component allows an authorized attacker to … | |
| CVE-2026-20842 | Medium | 0.4% | 7.0 | Use after free in Windows DWM allows an authorized attacker to elevate privilege… | |
| CVE-2026-20863 | Medium | 0.4% | 7.0 | Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate p… | |
| CVE-2026-20865 | Medium | 0.4% | 7.8 | Use after free in Windows Management Services allows an authorized attacker to e… | |
| CVE-2026-62816 | Medium | 0.4% | 8.8 | Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allow… | |
| CVE-2024-21405 | Medium | 0.4% | 7.0 | Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability | |
| CVE-2026-61925 | Medium | 0.4% | 7.8 | Incorrect authorization in Windows Installer allows an authorized attacker to el… | |
| CVE-2026-62712 | Medium | 0.4% | 7.8 | Heap-based buffer overflow in Windows Win32K allows an authorized attacker to el… | |
| CVE-2026-69585 | Medium | 0.4% | 7.8 | Incorrect type conversion or cast in Microsoft Windows Search Component allows a… | |
| CVE-2026-20809 | Medium | 0.4% | 7.8 | Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allow… |