← Back to Products

windows_11_23h2

Vendor: microsoft

163
Total CVEs
1
Critical
131
High
19
Medium
12
Low

Recent CVEs

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

8.1

CVSS

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

9.8

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.0

CVSS

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.0

CVSS

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.0

CVSS

Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.8

CVSS

Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.5

CVSS

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

8.8

CVSS

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

5.5

CVSS

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

5.5

CVSS

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

5.5

CVSS

Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

5.5

CVSS

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

5.5

CVSS

Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an unauthorized attacker to execute code locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.8

CVSS

Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

5.5

CVSS

Use after free in Windows User Interface Core allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.8

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.8

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.8

CVSS

Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

8.4

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.8

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.8

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.8

CVSS

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.8

CVSS

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.8

CVSS

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

6.5

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.0

CVSS

Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.3

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.0

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.0

CVSS

Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

5.5

CVSS

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

5.5

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.0

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.0

CVSS

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

5.5

CVSS

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

5.5

CVSS

Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.8

CVSS

Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.8

CVSS

Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.8

CVSS

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.0

CVSS

Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.8

CVSS

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.0

CVSS

Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

6.2

CVSS

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.5

CVSS

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.0

CVSS

Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.8

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.0

CVSS

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

5.5

CVSS

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

5.5

CVSS

Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.0

CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Projected File System allows an authorized attacker to elevate privileges locally....

Affected versions: 10.0.22621.2715 10.0.22621.4169 10.0.22621.4751 10.0.22621.5335 10.0.22631.2428 +40 more

Published: Apr 14, 2026

7.8

CVSS