Windows 11 24h2
Vendor:
First CVE: Dec 11, 2013 · Active for 12 years
1,728
Total CVEs
More Total CVEs than 100% of tracked products
432.0
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 49% of tracked products
2.6%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Windows 11 24h2 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 11, 2013
12 years ago
Most Recent CVE
Jul 16, 2026
12 days ago
CVE Severity & Scoring
Windows 11 24h21,728 CVEs
26%
71%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1,166 (67.5%)
Network421 (24.4%)
Unknown0 (0.0%)
Physical98 (5.7%)
Adjacent Network43 (2.5%)
Attack Complexity
Low1,330 (77.0%)
High398 (23.0%)
Unknown0 (0.0%)
User Interaction
None1,443 (83.5%)
Unknown0 (0.0%)
Required285 (16.5%)
Privileges Required
Low1,149 (66.5%)
High40 (2.3%)
None539 (31.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (1728 CVEs).
1,728 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-33073HIGH Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. | Jun 10, 2025 | 8.8 | 96 | YES | YES |
CVE-2025-33053HIGH External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network. | Jun 10, 2025 | 8.8 | 96 | YES | YES |
CVE-2026-32202MEDIUM Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. | Apr 14, 2026 | 4.3 | 93 | YES | YES |
CVE-2024-43451MEDIUM NTLM Hash Disclosure Spoofing Vulnerability | Nov 12, 2024 | 6.5 | 92 | YES | NO |
CVE-2025-24054MEDIUM External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | Mar 11, 2025 | 5.4 | 90 | YES | YES |
CVE-2024-43572HIGH Microsoft Management Console Remote Code Execution Vulnerability | Oct 8, 2024 | 7.8 | 90 | YES | NO |
CVE-2024-43461HIGH Windows MSHTML Platform Spoofing Vulnerability | Sep 10, 2024 | 8.8 | 88 | YES | NO |
CVE-2013-3900HIGH Why is Microsoft republishing a CVE from 2013?
We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the | Dec 11, 2013 | 8.8 | 86 | YES | NO |
CVE-2025-26633HIGH Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. | Mar 11, 2025 | 7.0 | 85 | YES | YES |
CVE-2024-49138HIGH Windows Common Log File System Driver Elevation of Privilege Vulnerability | Dec 12, 2024 | 7.8 | 85 | YES | YES |
Exploit Exposure
Signals from CVEs in this product scope (1728 CVEs).
CISA KEV
45 CVEs
2.6% of CVEs· 98th percentile
Metasploit
2 CVEs
0.1% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
21 CVEs
1.2% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (1728 CVEs).
Media Mentions
Signals from CVEs in this product scope (1728 CVEs).
Top CNAs Publishing CVEs For Windows 11 24h2
Top CWEs
Versions
No cataloged versions.