Microsoft

Windows 11 24h2

2157 vulnerabilities found.

Please note: This list may be incomplete. Data is provided in its original format, subject to change.
Media report
  • EPSS 0.31%
  • Published 08.09.2026 17:19:18
  • Last modified 12.09.2026 04:16:39

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Media report
  • EPSS 0.31%
  • Published 08.09.2026 17:19:17
  • Last modified 12.09.2026 04:16:39

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Media report
  • EPSS 0.31%
  • Published 08.09.2026 17:19:17
  • Last modified 12.09.2026 04:16:40

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Media report
  • EPSS 0.32%
  • Published 08.09.2026 17:19:16
  • Last modified 08.09.2026 19:19:34

Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally.

Warning Media report
  • EPSS 0.63%
  • Published 08.09.2026 17:19:13
  • Last modified 09.09.2026 05:18:17

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Media report
  • EPSS 0.25%
  • Published 08.09.2026 17:19:10
  • Last modified 10.09.2026 14:51:56

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

Media report
  • EPSS 0.24%
  • Published 08.09.2026 17:18:51
  • Last modified 10.09.2026 15:03:01

Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.

Media report
  • EPSS 0.72%
  • Published 08.09.2026 17:18:49
  • Last modified 10.09.2026 15:04:13

Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.

Media report
  • EPSS 0.51%
  • Published 08.09.2026 17:18:34
  • Last modified 10.09.2026 15:22:45

Buffer over-read in Windows Storage allows an unauthorized attacker to disclose information with a physical attack.

Media report
  • EPSS 0.19%
  • Published 08.09.2026 17:18:30
  • Last modified 10.09.2026 15:24:21

Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.