Microsoft Vulnerabilities and Affected Products
Vulnerabilities associated with Windows 11 version 21H2.
Products
Clear product- Windows Server 20194,131 vulnerabilities
- Windows Server 2019 (Server Core installation)4,034 vulnerabilities
- Windows 10 Version 18093,762 vulnerabilities
- Windows Server 20163,677 vulnerabilities
- Windows Server 20223,485 vulnerabilities
- Windows Server 2016 (Server Core installation)3,473 vulnerabilities
- Windows 10 Version 16073,184 vulnerabilities
- Windows 10 Version 21H23,063 vulnerabilities
- Windows Server 2012 R22,998 vulnerabilities
- Windows Server 2012 R2 (Server Core installation)2,853 vulnerabilities
- Windows Server 20122,824 vulnerabilities
- Windows Server 2012 (Server Core installation)2,691 vulnerabilities
- Windows 10 Version 22H22,565 vulnerabilities
- Windows 10 Version 15072,277 vulnerabilities
- Windows 11 Version 24H21,924 vulnerabilities
- Windows Server 20251,917 vulnerabilities
- Windows Server 2025 (Server Core installation)1,917 vulnerabilities
- Windows Server 2008 R2 Service Pack 11,874 vulnerabilities
- Windows Server 2008 R2 Service Pack 1 (Server Core installation)1,860 vulnerabilities
- Windows 11 Version 23H21,845 vulnerabilities
- Windows 11 version 22H21,776 vulnerabilities
- Windows Server 2022, 23H2 Edition (Server Core installation)1,725 vulnerabilities
- Windows Server 2008 Service Pack 2 (Server Core installation)1,667 vulnerabilities
- Windows Server 2008 Service Pack 21,664 vulnerabilities
- Windows 11 version 21H21,560 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-43583HIGH | Winlogon Elevation of Privilege VulnerabilityWinlogon Elevation of Privilege Vulnerability CWE-250Oct 8, 2024 | CVSS7.8v3.1 | EPSS1.34% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43599HIGH | Remote Desktop Client Remote Code Execution VulnerabilityRemote Desktop Client Remote Code Execution Vulnerability CWE-416Oct 8, 2024 | CVSS8.8v3.1 | EPSS1.35% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43585MEDIUM | Code Integrity Guard Security Feature Bypass VulnerabilityCode Integrity Guard Security Feature Bypass Vulnerability CWE-693Oct 8, 2024 | CVSS5.5v3.1 | EPSS0.488% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43584HIGH | Windows Scripting Engine Security Feature Bypass VulnerabilityWindows Scripting Engine Security Feature Bypass Vulnerability CWE-693Oct 8, 2024 | CVSS7.7v3.1 | EPSS0.538% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43582HIGH | Remote Desktop Protocol Server Remote Code Execution VulnerabilityRemote Desktop Protocol Server Remote Code Execution Vulnerability CWE-416Oct 8, 2024 | CVSS8.1v3.1 | EPSS3.16% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43574HIGH | Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution VulnerabilityMicrosoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability CWE-416Oct 8, 2024 | CVSS8.3v3.1 | EPSS1.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43572HIGH | Microsoft Management Console Remote Code Execution VulnerabilityMicrosoft Management Console Remote Code Execution Vulnerability CWE-707Oct 8, 2024 | CVSS7.8v3.1 | EPSS66.6% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43570MEDIUM | Windows Kernel Elevation of Privilege VulnerabilityWindows Kernel Elevation of Privilege Vulnerability CWE-416Oct 8, 2024 | CVSS6.4v3.1 | EPSS0.498% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43565HIGH | Windows Network Address Translation (NAT) Denial of Service VulnerabilityWindows Network Address Translation (NAT) Denial of Service Vulnerability CWE-125Oct 8, 2024 | CVSS7.5v3.1 | EPSS2.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43563HIGH | Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityWindows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability CWE-591Oct 8, 2024 | CVSS7.8v3.1 | EPSS0.456% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43562HIGH | Windows Network Address Translation (NAT) Denial of Service VulnerabilityWindows Network Address Translation (NAT) Denial of Service Vulnerability CWE-125Oct 8, 2024 | CVSS7.5v3.1 | EPSS2.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43561MEDIUM | Windows Mobile Broadband Driver Denial of Service VulnerabilityWindows Mobile Broadband Driver Denial of Service Vulnerability | CVSS6.5v3.1 | EPSS0.818% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43560HIGH | Microsoft Windows Storage Port Driver Elevation of Privilege VulnerabilityMicrosoft Windows Storage Port Driver Elevation of Privilege Vulnerability CWE-122Oct 8, 2024 | CVSS7.8v3.1 | EPSS3.43% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43559MEDIUM | Windows Mobile Broadband Driver Denial of Service VulnerabilityWindows Mobile Broadband Driver Denial of Service Vulnerability CWE-476Oct 8, 2024 | CVSS6.5v3.1 | EPSS0.818% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43558MEDIUM | Windows Mobile Broadband Driver Denial of Service VulnerabilityWindows Mobile Broadband Driver Denial of Service Vulnerability | CVSS6.5v3.1 | EPSS0.818% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43557MEDIUM | Windows Mobile Broadband Driver Denial of Service VulnerabilityWindows Mobile Broadband Driver Denial of Service Vulnerability | CVSS6.5v3.1 | EPSS0.818% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43556HIGH | Windows Graphics Component Elevation of Privilege VulnerabilityWindows Graphics Component Elevation of Privilege Vulnerability CWE-416Oct 8, 2024 | CVSS7.8v3.1 | EPSS0.716% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43555MEDIUM | Windows Mobile Broadband Driver Denial of Service VulnerabilityWindows Mobile Broadband Driver Denial of Service Vulnerability CWE-125Oct 8, 2024 | CVSS6.5v3.1 | EPSS0.818% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43553HIGH | NT OS Kernel Elevation of Privilege VulnerabilityNT OS Kernel Elevation of Privilege Vulnerability CWE-822Oct 8, 2024 | CVSS7.4v3.1 | EPSS0.499% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43551HIGH | Windows Storage Elevation of Privilege VulnerabilityWindows Storage Elevation of Privilege Vulnerability CWE-59Oct 8, 2024 | CVSS7.8v3.1 | EPSS0.632% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43550HIGH | Windows Secure Channel Spoofing VulnerabilityWindows Secure Channel Spoofing Vulnerability CWE-295Oct 8, 2024 | CVSS7.4v3.1 | EPSS1.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43547MEDIUM | Windows Kerberos Information Disclosure VulnerabilityWindows Kerberos Information Disclosure Vulnerability CWE-325Oct 8, 2024 | CVSS6.5v3.1 | EPSS0.652% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43546MEDIUM | Windows Cryptographic Information Disclosure VulnerabilityWindows Cryptographic Information Disclosure Vulnerability CWE-203Oct 8, 2024 | CVSS5.6v3.1 | EPSS0.627% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43536MEDIUM | Windows Mobile Broadband Driver Remote Code Execution VulnerabilityWindows Mobile Broadband Driver Remote Code Execution Vulnerability CWE-601Oct 8, 2024 | CVSS6.8v3.1 | EPSS0.621% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43528HIGH | Windows Secure Kernel Mode Elevation of Privilege VulnerabilityWindows Secure Kernel Mode Elevation of Privilege Vulnerability CWE-122Oct 8, 2024 | CVSS7.8v3.1 | EPSS0.527% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |