📦 Windows 11 21h2

by Microsoft

🔍 What is Windows 11 21h2?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-38199

CRITICAL CVSS 9.8 Aug 13, 2024

This critical vulnerability allows remote attackers to execute arbitrary code on Windows systems running the Line Printer Daemon (LPD) service. Attackers can exploit this without authentication by sen...

CVE-2024-38140

CRITICAL CVSS 9.8 Aug 13, 2024

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted packets to the Reliable Multicast Transport driver. It affects Windows sys...

CVE-2024-38063

CRITICAL CVSS 9.8 Aug 13, 2024

This critical vulnerability in Windows TCP/IP stack allows remote attackers to execute arbitrary code without authentication by sending specially crafted packets. It affects Windows systems with TCP/I...

CVE-2024-30080

CRITICAL CVSS 9.8 Jun 11, 2024

CVE-2024-30080 is a critical remote code execution vulnerability in Microsoft Message Queuing (MSMQ) that allows unauthenticated attackers to execute arbitrary code with SYSTEM privileges by sending s...

CVE-2023-36397

CRITICAL CVSS 9.8 Nov 14, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted PGM (Pragmatic General Multicast) protocol packets. It affects Windows sys...

CVE-2023-36910

CRITICAL CVSS 9.8 Aug 8, 2023

This vulnerability allows remote attackers to execute arbitrary code on systems running Microsoft Message Queuing (MSMQ) by sending specially crafted packets. Attackers can gain SYSTEM privileges with...

CVE-2023-35385

CRITICAL CVSS 9.8 Aug 8, 2023

This vulnerability allows remote attackers to execute arbitrary code on systems running Microsoft Message Queuing (MSMQ) by sending specially crafted packets. It affects Windows servers and workstatio...

CVE-2023-35365

CRITICAL CVSS 9.8 Jul 11, 2023

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Routing and Remote Access Service (RRAS) without authentication. Attackers can exploit improper input va...

CVE-2023-35367

CRITICAL CVSS 9.8 Jul 11, 2023

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running the Routing and Remote Access Service (RRAS) without authentication. It affects Windows servers and work...

CVE-2023-32057

CRITICAL CVSS 9.8 Jul 11, 2023

This vulnerability allows remote attackers to execute arbitrary code on systems running Microsoft Message Queuing (MSMQ) by sending specially crafted packets. It affects Windows systems with MSMQ enab...

CVE-2023-32014

CRITICAL CVSS 9.8 Jun 14, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted PGM (Pragmatic General Multicast) packets. It affects Windows systems with...

CVE-2023-29363

CRITICAL CVSS 9.8 Jun 14, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted PGM (Pragmatic General Multicast) packets. It affects Windows systems with...

CVE-2022-35744

CRITICAL CVSS 9.8 May 31, 2023

CVE-2022-35744 is a critical remote code execution vulnerability in Windows Point-to-Point Protocol (PPP) that allows unauthenticated attackers to execute arbitrary code on affected systems. This affe...

CVE-2023-24943

CRITICAL CVSS 9.8 May 9, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted PGM (Pragmatic General Multicast) protocol packets. It affects Windows sys...

CVE-2023-28250

CRITICAL CVSS 9.8 Apr 11, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted PGM (Pragmatic General Multicast) packets. It affects Windows systems with...

CVE-2023-21554

CRITICAL CVSS 9.8 Apr 11, 2023

This vulnerability allows remote attackers to execute arbitrary code on systems running Microsoft Message Queuing (MSMQ) by sending specially crafted packets. It affects Windows servers and workstatio...

CVE-2023-23415

CRITICAL CVSS 9.8 Mar 14, 2023

This critical vulnerability allows remote attackers to execute arbitrary code on affected systems by sending specially crafted ICMP packets. It affects Windows systems with specific network configurat...

CVE-2023-23392

CRITICAL CVSS 9.8 Mar 14, 2023

CVE-2023-23392 is a critical remote code execution vulnerability in the Windows HTTP Protocol Stack (http.sys) that allows unauthenticated attackers to execute arbitrary code with SYSTEM privileges by...

CVE-2023-21708

CRITICAL CVSS 9.8 Mar 14, 2023

This is a critical Remote Procedure Call Runtime vulnerability that allows unauthenticated attackers to execute arbitrary code remotely on affected Windows systems. It affects Windows servers and work...

CVE-2023-21689

CRITICAL CVSS 9.8 Feb 14, 2023

This vulnerability allows remote attackers to execute arbitrary code on systems running Microsoft's Protected Extensible Authentication Protocol (PEAP) without authentication. It affects Windows syste...

CVE-2024-43615

HIGH CVSS 7.1 Oct 8, 2024

This vulnerability in Microsoft OpenSSH for Windows allows remote attackers to execute arbitrary code on affected systems. Attackers could exploit this to gain control of Windows servers running vulne...

CVE-2024-43584

HIGH CVSS 7.7 Oct 8, 2024

This vulnerability allows attackers to bypass security features in the Windows Scripting Engine, potentially executing malicious scripts with elevated privileges. It affects Windows systems with the v...

CVE-2024-43574

HIGH CVSS 8.3 Oct 8, 2024

This vulnerability in Microsoft Speech API (SAPI) allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects systems running vulnerable ver...

CVE-2024-43582

HIGH CVSS 8.1 Oct 8, 2024

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running vulnerable Remote Desktop Protocol (RDP) servers. Attackers can exploit this without authentication to g...

CVE-2024-43572

HIGH CVSS 7.8 Oct 8, 2024

This vulnerability allows remote code execution through Microsoft Management Console (MMC). Attackers can exploit it to execute arbitrary code on affected systems, potentially gaining full control. Or...

CVE-2024-43562

HIGH CVSS 7.5 Oct 8, 2024

This vulnerability in Windows Network Address Translation (NAT) allows attackers to cause a denial of service condition by sending specially crafted network packets. It affects Windows systems with NA...

CVE-2024-43560

HIGH CVSS 7.8 Oct 8, 2024

This vulnerability in the Microsoft Windows Storage Port Driver allows an authenticated attacker to execute arbitrary code with SYSTEM privileges. It affects Windows systems where an attacker has loca...

CVE-2024-43553

HIGH CVSS 7.4 Oct 8, 2024

This CVE describes a Windows NT kernel elevation of privilege vulnerability that allows authenticated attackers to gain SYSTEM-level privileges on affected systems. It affects Windows operating system...

CVE-2024-43556

HIGH CVSS 7.8 Oct 8, 2024

This vulnerability in the Windows Graphics Component allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploiting a use-after-free condition. It affects Windows syst...

CVE-2024-43551

HIGH CVSS 7.8 Oct 8, 2024

This Windows Storage Elevation of Privilege vulnerability allows authenticated attackers to gain SYSTEM-level privileges on affected systems. It affects Windows operating systems where an attacker wit...

CVE-2024-43529

HIGH CVSS 7.3 Oct 8, 2024

This vulnerability allows attackers to elevate privileges on Windows systems by exploiting the Print Spooler service. Attackers could gain SYSTEM-level access on affected machines. All Windows systems...

CVE-2024-43533

HIGH CVSS 8.8 Oct 8, 2024

This vulnerability allows attackers to execute arbitrary code on systems running vulnerable Remote Desktop Client software by sending specially crafted requests. It affects users of Microsoft Remote D...

CVE-2024-43535

HIGH CVSS 7.0 Oct 8, 2024

This vulnerability allows attackers to gain elevated privileges on Windows systems by exploiting a use-after-free bug in the kernel-mode driver. It affects Windows systems with the vulnerable driver i...

CVE-2024-43516

HIGH CVSS 7.8 Oct 8, 2024

This vulnerability allows an authenticated attacker to execute arbitrary code in Windows Secure Kernel Mode, potentially gaining SYSTEM privileges. It affects Windows systems with Secure Kernel Mode e...

CVE-2024-43518

HIGH CVSS 8.8 Oct 8, 2024

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running the Telephony Server service. Attackers can exploit this heap-based buffer overflow (CWE-122) to gain SY...

CVE-2024-43509

HIGH CVSS 7.8 Oct 8, 2024

This Windows Graphics Component vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploiting a use-after-free memory corruption flaw. It affects Window...

CVE-2024-43514

HIGH CVSS 7.8 Oct 8, 2024

This vulnerability allows an authenticated attacker to exploit a double-free condition (CWE-415) in Windows Resilient File System (ReFS) to gain SYSTEM privileges. It affects Windows systems using ReF...

CVE-2024-43501

HIGH CVSS 7.8 Oct 8, 2024

This vulnerability in the Windows Common Log File System (CLFS) driver allows attackers to gain SYSTEM privileges by exploiting improper link resolution. It affects Windows systems where an attacker a...

CVE-2024-38149

HIGH CVSS 7.5 Oct 8, 2024

This vulnerability allows attackers to cause a denial of service (DoS) in BranchCache, a Windows feature that caches content from remote servers. Attackers can send specially crafted requests to Branc...

CVE-2024-20659

HIGH CVSS 7.1 Oct 8, 2024

This vulnerability allows attackers to bypass security features in Windows Hyper-V, potentially enabling unauthorized access or privilege escalation within virtualized environments. It affects systems...

CVE-2024-38257

HIGH CVSS 7.5 Sep 10, 2024

This vulnerability in Microsoft's AllJoyn API allows attackers to read sensitive information from memory without proper authorization. It affects systems running vulnerable versions of Windows that ha...

CVE-2024-38259

HIGH CVSS 8.8 Sep 10, 2024

This vulnerability allows remote attackers to execute arbitrary code on affected systems through the Microsoft Management Console (MMC). Attackers could gain SYSTEM privileges on Windows systems runni...

CVE-2024-38250

HIGH CVSS 7.8 Sep 10, 2024

This Windows Graphics Component vulnerability allows an attacker to gain SYSTEM-level privileges on affected systems by exploiting a buffer overflow condition. It affects Windows operating systems wit...

CVE-2024-38253

HIGH CVSS 7.8 Sep 10, 2024

This CVE describes an elevation of privilege vulnerability in the Windows Win32 Kernel Subsystem. An attacker who successfully exploits this vulnerability could gain SYSTEM-level privileges on a vulne...

CVE-2024-38246

HIGH CVSS 7.0 Sep 10, 2024

This CVE describes a Win32k elevation of privilege vulnerability in Windows systems. It allows an authenticated attacker to execute arbitrary code with SYSTEM privileges, potentially taking full contr...

CVE-2024-38248

HIGH CVSS 7.0 Sep 10, 2024

This Windows Storage Elevation of Privilege vulnerability allows an authenticated attacker to gain SYSTEM-level privileges by exploiting a use-after-free condition in Windows Storage components. It af...

CVE-2024-38242

HIGH CVSS 7.8 Sep 10, 2024

This vulnerability allows attackers to gain elevated privileges on Windows systems by exploiting a heap-based buffer overflow in the Kernel Streaming Service Driver. It affects Windows systems where a...

CVE-2024-38244

HIGH CVSS 7.8 Sep 10, 2024

This vulnerability allows attackers to elevate privileges on Windows systems by exploiting a flaw in the Kernel Streaming Service Driver. Attackers with initial access to a system can gain SYSTEM-leve...

CVE-2024-38238

HIGH CVSS 7.8 Sep 10, 2024

This is a Windows kernel driver vulnerability in the Kernel Streaming Service that allows local attackers to escalate privileges from a low-privileged account to SYSTEM level. It affects Windows syste...

CVE-2024-38240

HIGH CVSS 8.1 Sep 10, 2024

This vulnerability allows an authenticated attacker to elevate privileges on Windows systems by exploiting a flaw in the Remote Access Connection Manager service. Attackers could gain SYSTEM-level acc...

CVE-2024-38046

HIGH CVSS 7.8 Sep 10, 2024

This PowerShell vulnerability allows authenticated attackers to execute arbitrary code with elevated privileges on affected systems. It affects Windows systems with PowerShell installed, primarily imp...

CVE-2024-30073

HIGH CVSS 7.8 Sep 10, 2024

This vulnerability allows attackers to bypass Windows Security Zone mapping protections, potentially tricking users into executing malicious content from untrusted locations as if they were from trust...

CVE-2024-38163

HIGH CVSS 7.8 Aug 14, 2024

This vulnerability in the Windows Update Stack allows an authenticated attacker to execute arbitrary code with SYSTEM privileges. It affects Windows systems where an attacker has local access and can ...

CVE-2024-38215

HIGH CVSS 7.8 Aug 13, 2024

This vulnerability in the Windows Cloud Files Mini Filter Driver allows an attacker to gain SYSTEM-level privileges on affected systems. It affects Windows 10, 11, Server 2019, and Server 2022. An att...

CVE-2024-38198

HIGH CVSS 7.5 Aug 13, 2024

This vulnerability allows attackers to gain elevated privileges on Windows systems by exploiting the Print Spooler service. Attackers could execute arbitrary code with SYSTEM privileges. All Windows s...

CVE-2024-38187

HIGH CVSS 7.8 Aug 13, 2024

This vulnerability allows an authenticated attacker to exploit a flaw in a Windows kernel-mode driver to gain SYSTEM-level privileges. It affects Windows systems where an attacker already has local us...

CVE-2024-38191

HIGH CVSS 7.8 Aug 13, 2024

This CVE describes an elevation of privilege vulnerability in the Windows Kernel Streaming Service Driver. It allows authenticated attackers to execute arbitrary code with SYSTEM privileges, affecting...

CVE-2024-38180

HIGH CVSS 8.8 Aug 13, 2024

This vulnerability allows attackers to bypass Windows SmartScreen security checks, potentially enabling them to execute malicious files without proper warnings. It affects Windows systems with SmartSc...

CVE-2024-38185

HIGH CVSS 7.8 Aug 13, 2024

This vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploiting a flaw in the Windows kernel-mode driver. It affects Windows systems where an attacke...

CVE-2024-38146

HIGH CVSS 7.5 Aug 13, 2024

This vulnerability in the Windows Layer-2 Bridge Network Driver allows an attacker to cause a denial of service (system crash/BSOD) by sending specially crafted network packets. It affects Windows sys...

CVE-2022-40733

MEDIUM CVSS 5.0 Dec 18, 2024

This CVE describes an access violation vulnerability in the DirectComposition functionality of the win32kbase.sys driver on Windows 11 and Windows Server 2022. An unprivileged user can trigger a denia...

CVE-2024-43558

MEDIUM CVSS 6.5 Oct 8, 2024

This vulnerability in the Windows Mobile Broadband Driver allows an attacker to cause a denial of service (system crash/BSOD) by sending specially crafted network packets. It affects Windows systems w...

CVE-2024-43555

MEDIUM CVSS 6.5 Oct 8, 2024

This vulnerability in the Windows Mobile Broadband Driver allows attackers to cause a denial of service (system crash/BSOD) by sending specially crafted requests. It affects Windows systems with mobil...

CVE-2024-43543

MEDIUM CVSS 6.8 Oct 8, 2024

This vulnerability in the Windows Mobile Broadband Driver allows remote attackers to execute arbitrary code on affected systems. Attackers could exploit this by sending specially crafted packets to vu...

CVE-2024-43546

MEDIUM CVSS 5.6 Oct 8, 2024

This Windows vulnerability allows attackers to obtain cryptographic information that could help them decrypt protected data or bypass security mechanisms. It affects Windows systems with specific cryp...

CVE-2024-43537

MEDIUM CVSS 6.5 Oct 8, 2024

This vulnerability in the Windows Mobile Broadband Driver allows attackers to cause a denial of service (system crash) by sending specially crafted requests. It affects Windows systems with mobile bro...

CVE-2024-43540

MEDIUM CVSS 6.5 Oct 8, 2024

This vulnerability in the Windows Mobile Broadband Driver allows attackers to cause a denial of service (system crash/BSOD) by sending specially crafted requests. It affects Windows systems with mobil...

CVE-2024-43525

MEDIUM CVSS 6.8 Oct 8, 2024

This vulnerability in the Windows Mobile Broadband Driver allows an attacker to execute arbitrary code remotely on affected systems. Attackers could exploit this to gain control over vulnerable Window...

CVE-2024-43520

MEDIUM CVSS 5.0 Oct 8, 2024

This Windows kernel vulnerability allows attackers to cause a denial of service (system crash/BSOD) by exploiting a NULL pointer dereference. It affects Windows systems with the vulnerable kernel comp...

CVE-2024-43523

MEDIUM CVSS 6.8 Oct 8, 2024

This vulnerability in the Windows Mobile Broadband Driver allows attackers to execute arbitrary code remotely on affected systems. It affects Windows devices with mobile broadband hardware/software. A...

CVE-2024-37982

MEDIUM CVSS 6.7 Oct 8, 2024

This vulnerability allows attackers to bypass security features in Windows Resume Extensible Firmware Interface (Resume EFI) during system resume operations. It affects Windows systems with Resume EFI...

CVE-2024-37976

MEDIUM CVSS 6.7 Oct 8, 2024

This vulnerability allows attackers to bypass security features in Windows Resume Extensible Firmware Interface (Resume EFI) during system resume operations. It affects Windows systems with Resume EFI...

CVE-2024-38234

MEDIUM CVSS 6.5 Sep 10, 2024

CVE-2024-38234 is a Windows networking vulnerability that allows attackers to cause denial of service by sending specially crafted network packets to affected systems. This affects Windows servers and...

CVE-2024-38161

MEDIUM CVSS 6.8 Aug 13, 2024

This vulnerability in the Windows Mobile Broadband Driver allows attackers to execute arbitrary code remotely on affected systems. It affects Windows devices with mobile broadband hardware/software en...

CVE-2024-38151

MEDIUM CVSS 5.5 Aug 13, 2024

This Windows kernel vulnerability allows attackers to read sensitive kernel memory information, potentially exposing system details or credentials. It affects Windows systems with the vulnerable kerne...

CVE-2024-38122

MEDIUM CVSS 5.5 Aug 13, 2024

This vulnerability in Microsoft's Local Security Authority (LSA) server allows authenticated attackers to disclose sensitive information from system memory. It affects Windows systems where an attacke...

CVE-2024-38118

MEDIUM CVSS 5.5 Aug 13, 2024

This vulnerability in Microsoft's Local Security Authority (LSA) Server allows an authenticated attacker to read sensitive information from memory. It affects Windows systems where an attacker has alr...

CVE-2024-38102

MEDIUM CVSS 6.5 Jul 9, 2024

This vulnerability in the Windows Layer-2 Bridge Network Driver allows an attacker to cause a denial of service (system crash/BSOD) by sending specially crafted network packets. It affects Windows sys...

CVE-2024-38056

MEDIUM CVSS 5.5 Jul 9, 2024

This vulnerability in Microsoft Windows Codecs Library allows an attacker to read sensitive information from memory that should be inaccessible. It affects Windows systems with the vulnerable codecs l...

CVE-2024-38049

MEDIUM CVSS 6.6 Jul 9, 2024

CVE-2024-38049 is a remote code execution vulnerability in Windows Distributed Transaction Coordinator (MSDTC) that allows an authenticated attacker to execute arbitrary code with SYSTEM privileges on...

CVE-2024-38041

MEDIUM CVSS 5.5 Jul 9, 2024

CVE-2024-38041 is a Windows kernel information disclosure vulnerability that allows attackers to read sensitive kernel memory contents. This affects Windows systems where an attacker has local access ...

CVE-2024-35270

MEDIUM CVSS 5.3 Jul 9, 2024

This vulnerability in the Windows iSCSI service allows attackers to cause a denial of service (DoS) by sending specially crafted packets to affected systems. It affects Windows servers and workstation...

CVE-2024-30071

MEDIUM CVSS 4.7 Jul 9, 2024

This vulnerability in Windows Remote Access Connection Manager allows an authenticated attacker to read sensitive information from system memory. It affects Windows systems with Remote Access Connecti...

CVE-2024-26184

MEDIUM CVSS 6.8 Jul 9, 2024

CVE-2024-26184 is a Secure Boot security feature bypass vulnerability that allows attackers to circumvent Secure Boot protections on affected systems. This could enable loading of unauthorized or mali...

CVE-2024-30096

MEDIUM CVSS 5.5 Jun 11, 2024

This vulnerability in Windows Cryptographic Services allows an attacker to read sensitive information from memory that should be protected. It affects Windows systems where cryptographic operations ar...

CVE-2024-30076

MEDIUM CVSS 6.8 Jun 11, 2024

This vulnerability allows an authenticated attacker to escalate privileges within Windows Container Manager Service. Attackers could gain SYSTEM-level access on affected Windows systems. Only systems ...

CVE-2024-30066

MEDIUM CVSS 5.5 Jun 11, 2024

CVE-2024-30066 is a Winlogon elevation of privilege vulnerability in Windows that allows authenticated attackers to gain SYSTEM privileges. This affects Windows systems where an attacker already has l...

CVE-2024-30037

MEDIUM CVSS 5.5 May 14, 2024

This vulnerability in the Windows Common Log File System (CLFS) driver allows an authenticated attacker to gain SYSTEM privileges through a local exploit. It affects Windows systems with the vulnerabl...

CVE-2024-30016

MEDIUM CVSS 5.5 May 14, 2024

CVE-2024-30016 is an information disclosure vulnerability in Windows Cryptographic Services that could allow an attacker to read sensitive information from memory. This affects Windows systems where c...

CVE-2024-30008

MEDIUM CVSS 5.5 May 14, 2024

This vulnerability in the Windows Desktop Window Manager (DWM) Core Library allows an attacker to read sensitive information from memory. It affects Windows systems where an attacker could gain access...