Microsoft
Microsoft Windows 11: vulnerabilidades y CVE
Microsoft Windows 11 tiene 579 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 17 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE579
Últimos 12 meses1
Críticas17
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-40449 | Alta (7.8) | 74% | ⚠ Explotación activa | 13 oct 2021 | Win32k Elevation of Privilege Vulnerability |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-2636 | Media (5.5) | 0.43% | — | 25 feb 2026 | This vulnerability is caused by a CWE‑159: "Improper Handling of Invalid Use of Special Elements" weakness, which leads to an unrecoverable inconsistency in the CLFS.sys driver. This condition forces a call to the… |
| CVE-2025-40979 | Alta (7) | 0.14% | — | 10 sept 2025 | DLL search order hijacking vulnerability in the wave.exe executable for Windows 11, version 1.27.8. Exploitation of this vulnerability could allow attackers with local access to execute arbitrary code by placing an… |
| CVE-2025-7676 | Media (5.4) | 0.14% | — | 28 jul 2025 | DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute code, if the attacker can plant a DLL in the same directory as the executable. Vulnerable versions… |
| CVE-2024-6769 | Alta (8.4) | 1.1% | — | 26 sept 2024 | A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious… |
| CVE-2024-6768 | Media (6.8) | 2.5% | — | 12 ago 2024 | A Denial of Service in CLFS.sys in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated low-privilege user to cause a Blue Screen of Death… |
| CVE-2017-20190 | Sin puntuar | 0.26% | — | 27 mar 2024 | Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side performance degradation during processing of multiple Unicode combining characters, aka a "Zalgo text" attack. NOTE: third… |
| CVE-2023-44216 | Media (5.3) | 1.6% | — | 27 sept 2023 | PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter… |
| CVE-2023-21776 | Media (5.5) | 1.0% | — | 10 ene 2023 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2023-21771 | Alta (7) | 0.40% | — | 10 ene 2023 | Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability |
| CVE-2023-21768 | Alta (7.8) | 65% | — | 10 ene 2023 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2023-21767 | Alta (7.8) | 0.46% | — | 10 ene 2023 | Windows Overlay Filter Elevation of Privilege Vulnerability |
| CVE-2023-21766 | Media (4.7) | 0.87% | — | 10 ene 2023 | Windows Overlay Filter Information Disclosure Vulnerability |
| CVE-2023-21765 | Alta (7.8) | 0.47% | — | 10 ene 2023 | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2023-21760 | Alta (7.1) | 0.53% | — | 10 ene 2023 | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2023-21759 | Baja (3.3) | 0.59% | — | 10 ene 2023 | Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability |
| CVE-2023-21758 | Alta (7.5) | 93% | — | 10 ene 2023 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability |
| CVE-2023-21757 | Alta (7.5) | 2.0% | — | 10 ene 2023 | Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability |
| CVE-2023-21752 | Alta (7.1) | 5.3% | — | 10 ene 2023 | Windows Backup Service Elevation of Privilege Vulnerability |
| CVE-2023-21746 | Alta (7.8) | 2.5% | — | 10 ene 2023 | Windows NTLM Elevation of Privilege Vulnerability |
| CVE-2023-21558 | Alta (7.8) | 0.46% | — | 10 ene 2023 | Windows Error Reporting Service Elevation of Privilege Vulnerability |
| CVE-2022-44710 | Alta (7.8) | 0.61% | — | 13 dic 2022 | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2022-44707 | Media (6.5) | 2.6% | — | 13 dic 2022 | Windows Kernel Denial of Service Vulnerability |
| CVE-2022-44697 | Alta (7.8) | 0.53% | — | 13 dic 2022 | Windows Graphics Component Elevation of Privilege Vulnerability |
| CVE-2022-44689 | Alta (7.8) | 0.49% | — | 13 dic 2022 | Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability |
| CVE-2022-44683 | Alta (7.8) | 8.2% | — | 13 dic 2022 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2022-44682 | Media (6.8) | 0.72% | — | 13 dic 2022 | Windows Hyper-V Denial of Service Vulnerability |
| CVE-2022-44681 | Alta (7.8) | 0.53% | — | 13 dic 2022 | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2022-44680 | Alta (7.8) | 0.51% | — | 13 dic 2022 | Windows Graphics Component Elevation of Privilege Vulnerability |
| CVE-2022-44679 | Media (6.5) | 0.54% | — | 13 dic 2022 | Windows Graphics Component Information Disclosure Vulnerability |
| CVE-2022-44678 | Alta (7.8) | 0.55% | — | 13 dic 2022 | Windows Print Spooler Elevation of Privilege Vulnerability |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.