← Vulnerability feed

Vulnerability record · CVE-2023-24902 · published 9 May 2023

CVE-2023-24902: Microsoft windows 11 21h2 out-of-bounds read vulnerability

Microsoft · Windows 11 21h2

Win32k Elevation of Privilege Vulnerability

7.8 CVSS 3.1 High EPSS 5.1% · top 7.9% CWE-125 · Out-of-bounds read
7.8CVSS 3.1 base score
5.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Win32k Elevation of Privilege Vulnerability

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-24902 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-33073Windows SMB improper access control allows privilege elevationWindows SMB contains an improper access control flaw (CWE-284) that lets an authorized attacker elevate privileges over the network. Microsoft rates …KEVEPSS 83%analysed8.8CVE-2025-33053Microsoft Windows WebDAV Internet Shortcut File Path Control RCEWindows Internet Shortcut (.url) files allow external control of a file name or path, which an unauthorized attacker can abuse to execute code over a…KEVEPSS 87%analysed8.8CVE-2024-49039Windows Task Scheduler elevation of privilege via improper authenticationCVE-2024-49039 is an elevation of privilege flaw in the Windows Task Scheduler, classified as improper authentication (CWE-287). A local attacker wit…KEVEPSS 14%analysed8.8CVE-2024-43461Windows MSHTML Platform spoofing flaw enables code executionCVE-2024-43461 is a spoofing vulnerability in the Windows MSHTML platform, the legacy rendering engine still reachable through Windows components. Th…KEVEPSS 54%analysed8.8CVE-2024-30040Windows MSHTML platform security feature bypass via improper input validationCVE-2024-30040 is a security feature bypass in the Windows MSHTML platform caused by improper input validation. Because MSHTML is the legacy renderin…KEVEPSS 3.9%analysed8.8CVE-2024-29988Microsoft Windows SmartScreen Prompt Security Feature BypassCVE-2024-29988 is a security feature bypass in the Microsoft Windows SmartScreen prompt. An attacker can craft a file or content that evades the Smar…KEVEPSS 45%analysed8.8CVE-2023-36025Windows SmartScreen security feature bypassCVE-2023-36025 is a security feature bypass in Microsoft Windows SmartScreen, the component that warns users before running files downloaded from the…KEVEPSS 88%analysed8.8CVE-2023-32049Windows SmartScreen security feature bypassCVE-2023-32049 is a security feature bypass in Microsoft Windows SmartScreen, the component that warns users about untrusted files and downloads. A s…KEVEPSS 4.2%analysed

Source: NIST National Vulnerability Database (record CVE-2023-24902), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.