Showing 25 vulnerabilities on this page for Windows 11 version 22H2

Signals CISA KEV Ransomware Nuclei
Microsoft vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Windows NTLM Spoofing Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

CWE-200Jun 9, 2026
CVSS6.5v3.1EPSS8.68%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows DWM Core Library Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CWE-122Dec 9, 2025
CVSS7.8v3.1EPSS0.365%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows DWM Core Library Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CWE-122Dec 9, 2025
CVSS7.8v3.1EPSS0.459%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows License Manager Information Disclosure Vulnerability

Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.

CWE-532Nov 11, 2025
CVSS5.5v3.1EPSS0.515%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows License Manager Information Disclosure Vulnerability

Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.

CWE-532Nov 11, 2025
CVSS5.5v3.1EPSS0.515%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows Bluetooth Service Elevation of Privilege Vulnerability

Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

CWE-415Oct 14, 2025
CVSS7.0v3.1EPSS0.22%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows Authentication Elevation of Privilege Vulnerability

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

CWE-1287Oct 14, 2025
CVSS7.8v3.1EPSS0.255%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows Authentication Elevation of Privilege Vulnerability

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

CVSS7.8v3.1EPSS0.255%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows Graphics Component Elevation of Privilege Vulnerability

Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

CWE-367Oct 14, 2025
CVSS7.0v3.1EPSS0.178%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows Search Service Denial of Service Vulnerability

Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.

CWE-284Oct 14, 2025
CVSS5.5v3.1EPSS0.314%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

CWE-284Oct 14, 2025
CVSS7.8v3.1EPSS2.58%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

NTLM Hash Disclosure Spoofing Vulnerability

External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.

CWE-73Oct 14, 2025
CVSS6.5v3.1EPSS0.764%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Windows File Explorer Spoofing Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

CWE-200Oct 14, 2025
CVSS6.5v3.1EPSS1.78%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows Push Notification Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.

CWE-200Oct 14, 2025
CVSS5.5v3.1EPSS0.436%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows MapUrlToZone Information Disclosure Vulnerability

Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network.

CWE-125Oct 14, 2025
CVSS7.1v3.1EPSS0.466%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows Graphics Component Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

CWE-362Oct 14, 2025
CVSS7.0v3.1EPSS0.185%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows State Repository API Server File Information Disclosure Vulnerability

Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally.

CWE-532Oct 14, 2025
CVSS5.5v3.1EPSS0.42%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows Search Service Denial of Service Vulnerability

Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.

CWE-20Oct 14, 2025
CVSS5.0v3.1EPSS0.442%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows ETL Channel Information Disclosure Vulnerability

Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally.

CWE-532Oct 14, 2025
CVSS5.5v3.1EPSS0.42%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows Kernel Elevation of Privilege Vulnerability

Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally.

CWE-908Oct 14, 2025
CVSS7.0v3.1EPSS2.5%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows Management Services Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

CWE-362Oct 14, 2025
CVSS7.0v3.1EPSS0.178%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Storport.sys Driver Elevation of Privilege Vulnerability

Buffer over-read in Storport.sys Driver allows an authorized attacker to elevate privileges locally.

CWE-126Oct 14, 2025
CVSS7.8v3.1EPSS0.274%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows Connected Devices Platform Service Elevation of Privilege Vulnerability

Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

CWE-122Oct 14, 2025
CVSS7.8v3.1EPSS0.296%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows Search Service Denial of Service Vulnerability

Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.

CWE-20Oct 14, 2025
CVSS5.5v3.1EPSS0.467%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Windows Kernel Elevation of Privilege Vulnerability

Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally.

CWE-20CWE-822Oct 14, 2025
CVSS7.8v3.1EPSS0.285%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX