Windows 11 24h2 Microsoft Windows 11 24h2

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Microsoft Windows 11 24h2.

By the Year

In 2025 there have been 324 vulnerabilities in Microsoft Windows 11 24h2 with an average score of 7.2 out of ten. Last year, in 2024 Windows 11 24h2 had 216 security vulnerabilities published. That is, 108 more vulnerabilities have already been reported in 2025 as compared to last year. Last year, the average CVE base score was greater by 0.23

Year Vulnerabilities Average Score
2025 324 7.20
2024 216 7.43
2023 0 0.00
2022 0 0.00
2021 0 0.00
2020 0 0.00
2019 0 0.00
2018 0 0.00

It may take a day or so for new Windows 11 24h2 vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Microsoft Windows 11 24h2 Security Vulnerabilities

Exposure of sensitive information to an unauthorized actor in Windows Hello

CVE-2025-47969 4.4 - Medium - June 10, 2025

Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally.

Information Disclosure

Improper privilege management in Windows Remote Access Connection Manager

CVE-2025-47955 7.8 - High - June 10, 2025

Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Improper Privilege Management

Protection mechanism failure in Windows Shell

CVE-2025-47160 5.4 - Medium - June 10, 2025

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

Protection Mechanism Failure

Improper link resolution before file access ('link following') in Windows Installer

CVE-2025-33075 7.8 - High - June 10, 2025

Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.

insecure temporary file

Improper access control in Windows SMB

CVE-2025-33073 8.8 - High - June 10, 2025

Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.

Authorization

Use of uninitialized resource in Windows Netlogon

CVE-2025-33070 8.1 - High - June 10, 2025

Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.

Use of Uninitialized Resource

External control of file name or path in Internet Shortcut Files

CVE-2025-33053 8.8 - High - June 10, 2025

External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.

External Control of File Name or Path

Improper verification of cryptographic signature in App Control for Business (WDAC)

CVE-2025-33069 5.1 - Medium - June 10, 2025

Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature locally.

Improper Verification of Cryptographic Signature

Improper privilege management in Windows Kernel

CVE-2025-33067 8.4 - High - June 10, 2025

Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

Improper Privilege Management

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS)

CVE-2025-33066 8.8 - High - June 10, 2025

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Heap-based Buffer Overflow

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS)

CVE-2025-33064 8.8 - High - June 10, 2025

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

Heap-based Buffer Overflow

Null pointer dereference in Windows Local Security Authority (LSA)

CVE-2025-33057 6.5 - Medium - June 10, 2025

Null pointer dereference in Windows Local Security Authority (LSA) allows an authorized attacker to deny service over a network.

NULL Pointer Dereference

Improper access control in Microsoft Local Security Authority Server (lsasrv)

CVE-2025-33056 7.5 - High - June 10, 2025

Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network.

Authorization

Use of uninitialized resource in Windows DWM Core Library

CVE-2025-33052 5.5 - Medium - June 10, 2025

Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally.

Use of Uninitialized Resource

Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS)

CVE-2025-32724 7.5 - High - June 10, 2025

Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

Resource Exhaustion

Improper access control in Windows Storage Port Driver

CVE-2025-32722 5.5 - Medium - June 10, 2025

Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally.

Authorization

Improper link resolution before file access ('link following') in Windows Recovery Driver

CVE-2025-32721 7.3 - High - June 10, 2025

Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally.

insecure temporary file

Out-of-bounds read in Windows Storage Management Provider

CVE-2025-32719 5.5 - Medium - June 10, 2025

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Out-of-bounds Read

Out-of-bounds read in Windows Storage Management Provider

CVE-2025-32720 5.5 - Medium - June 10, 2025

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Out-of-bounds Read

Out-of-bounds read in Windows Storage Management Provider

CVE-2025-33058 5.5 - Medium - June 10, 2025

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Out-of-bounds Read

Out-of-bounds read in Windows Storage Management Provider

CVE-2025-33059 5.5 - Medium - June 10, 2025

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Out-of-bounds Read

Out-of-bounds read in Windows Storage Management Provider

CVE-2025-33060 5.5 - Medium - June 10, 2025

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Out-of-bounds Read

Out-of-bounds read in Windows Storage Management Provider

CVE-2025-33061 5.5 - Medium - June 10, 2025

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Out-of-bounds Read

Out-of-bounds read in Windows Storage Management Provider

CVE-2025-33062 5.5 - Medium - June 10, 2025

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Out-of-bounds Read

Out-of-bounds read in Windows Storage Management Provider

CVE-2025-33063 5.5 - Medium - June 10, 2025

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Out-of-bounds Read

Out-of-bounds read in Windows Storage Management Provider

CVE-2025-33065 5.5 - Medium - June 10, 2025

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Out-of-bounds Read

Out-of-bounds read in Windows Storage Management Provider

CVE-2025-33055 5.5 - Medium - June 10, 2025

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Out-of-bounds Read

Out-of-bounds read in Windows Storage Management Provider

CVE-2025-24069 5.5 - Medium - June 10, 2025

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Out-of-bounds Read

Missing release of memory after effective lifetime in Windows Cryptographic Services

CVE-2025-29828 8.1 - High - June 10, 2025

Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to execute code over a network.

Memory Leak

Use after free in Windows Win32K - GRFX

CVE-2025-32712 7.8 - High - June 10, 2025

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

Dangling pointer

Heap-based buffer overflow in Windows Common Log File System Driver

CVE-2025-32713 7.8 - High - June 10, 2025

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Improper access control in Windows Installer

CVE-2025-32714 7.8 - High - June 10, 2025

Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally.

Authorization

Integer overflow or wraparound in Windows SMB

CVE-2025-32718 7.8 - High - June 10, 2025

Integer overflow or wraparound in Windows SMB allows an authorized attacker to elevate privileges locally.

Integer Overflow or Wraparound

Out-of-bounds read in Windows Storage Management Provider

CVE-2025-24065 5.5 - Medium - June 10, 2025

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Out-of-bounds Read

Buffer over-read in Windows Storage Management Provider

CVE-2025-24068 5.5 - Medium - June 10, 2025

Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Buffer Over-read

Out-of-bounds read in Remote Desktop Client

CVE-2025-32715 6.5 - Medium - June 10, 2025

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

Out-of-bounds Read

Use after free in Windows Common Log File System Driver

CVE-2025-30385 7.8 - High - May 13, 2025

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Dangling pointer

Use after free in Windows Ancillary Function Driver for WinSock

CVE-2025-32709 7.8 - High - May 13, 2025

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Dangling pointer

Improper input validation in Windows Common Log File System Driver

CVE-2025-32706 7.8 - High - May 13, 2025

Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Improper Input Validation

Use after free in Windows Common Log File System Driver

CVE-2025-32701 7.8 - High - May 13, 2025

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Dangling pointer

Use after free in Windows DWM

CVE-2025-30400 7.8 - High - May 13, 2025

Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

Dangling pointer

Heap-based buffer overflow in Windows Win32K - GRFX

CVE-2025-30388 7.8 - High - May 13, 2025

Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.

Memory Corruption

Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine

CVE-2025-30397 7.5 - High - May 13, 2025

Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.

Object Type Confusion

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS)

CVE-2025-29832 6.5 - Medium - May 13, 2025

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Out-of-bounds Read

Heap-based buffer overflow in Remote Desktop Gateway Service

CVE-2025-29967 8.8 - High - May 13, 2025

Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

Memory Corruption

Use of uninitialized resource in Windows Trusted Runtime Interface Driver

CVE-2025-29829 5.5 - Medium - May 13, 2025

Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.

Use of Uninitialized Resource

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS)

CVE-2025-29830 6.5 - Medium - May 13, 2025

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Use of Uninitialized Resource

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS)

CVE-2025-29835 6.5 - Medium - May 13, 2025

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Out-of-bounds Read

Heap-based buffer overflow in Windows Media

CVE-2025-29962 8.8 - High - May 13, 2025

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.

Memory Corruption

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS)

CVE-2025-29836 6.5 - Medium - May 13, 2025

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Out-of-bounds Read

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Microsoft Windows 11 24h2 or by Microsoft? Click the Watch button to subscribe.

Microsoft
Vendor

subscribe