Does Windows 11 have security issues?

  1. Home
  2. News

Does Windows 11 have security issues?

(Image credit: Microsoft)

The latest security patch for Windows 11, KB5015814, appears to be giving a growing number of users a hard time, with error codes aplenty on installation and even a few cases of boot looping. As this is a security update, it's not the sort of patch you really want to ignore either, as it could lead to your machine being compromised if you decide to postpone it. Not much fun.

The patch notes include a single line for the highlights of the update:

  • Addresses security issues for your Windows operating system. 

Great, thanks Microsoft. There is a bit more information lower down the page though, including the fact that this patch includes the improvements introduced with KB5014668 (opens in new tab) and that PowerShell transcript logs have been fixed—hardly something that affects most, but I'm sure our IT department will be delighted by the news.

There's also a known issue with .Net Framework 3.5 apps failing to open and exhibiting general issues. Some users have found that turning off the .Net Framework 3.5 before installation can help. Turning off Malwarebytes beforehand can also help matters here. There is a workaround on the patch notes page (opens in new tab), which could come in handy.

Another known problem affects IE mode in Microsoft Edge. Apparently, model dialog boxes can stop Edge from responding, which isn't ideal. The solution here is to use Known Issue Rollback (opens in new tab)—this is utterly broken in other words. While there probably aren't many users running IE mode, as it's essentially there to support older sites that require the now deprecated Internet Explorer 11, it's going to be annoying for anyone that has to rely on it.

This isn't the first time users have had problems with such security updates that are applied automatically and the curse of Patch Tuesday has become a bit of a thing because of it. It probably won't be the last time there are problems either. 

While these patch problems are relatively minor, there's nothing to stop more serious problems from appearing in the future. Your best recourse is to keep your machine backed up, you know, just in case. But of course, you do that already, don't you. Don't you?

Thanks, The Register. (opens in new tab)

Alan has been writing about PC tech since before 3D graphics cards existed, and still vividly recalls having to fight with MS-DOS just to get games to load. He fondly remembers the killer combo of a Matrox Millenium and 3dfx Voodoo, and seeing Lara Croft in 3D for the first time. He's very glad hardware has advanced as much as it has though, and is particularly happy when putting the latest M.2 NVMe SSDs, AMD processors, and laptops through their paces. He has a long-lasting Magic: The Gathering obsession but limits this to MTG Arena these days.

Cpe Name:cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:x64:*

# CVE ID CWE ID # of Exploits Vulnerability Type(s) Publish Date Update Date Score Gained Access Level Access Complexity Authentication Conf. Integ. Avail.
1 CVE-2022-41081 Exec Code 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22035, CVE-2022-24504, CVE-2022-30198, CVE-2022-33634, CVE-2022-38000, CVE-2022-38047.
2 CVE-2022-41033 2022-10-11 2022-10-13

0.0

None ??? ??? ??? ??? ??? ???
Windows COM+ Event System Service Elevation of Privilege Vulnerability.
3 CVE-2022-38051 2022-10-11 2022-10-13

0.0

None ??? ??? ??? ??? ??? ???
Windows Graphics Component Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37997.
4 CVE-2022-38050 2022-10-11 2022-10-13

0.0

None ??? ??? ??? ??? ??? ???
Win32k Elevation of Privilege Vulnerability.
5 CVE-2022-38047 362 Exec Code 2022-10-11 2022-10-13

0.0

None ??? ??? ??? ??? ??? ???
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22035, CVE-2022-24504, CVE-2022-30198, CVE-2022-33634, CVE-2022-38000, CVE-2022-41081.
6 CVE-2022-38046 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Web Account Manager Information Disclosure Vulnerability.
7 CVE-2022-38045 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Server Service Remote Protocol Elevation of Privilege Vulnerability.
8 CVE-2022-38044 Exec Code 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows CD-ROM File System Driver Remote Code Execution Vulnerability.
9 CVE-2022-38043 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Security Support Provider Interface Information Disclosure Vulnerability.
10 CVE-2022-38042 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Active Directory Domain Services Elevation of Privilege Vulnerability.
11 CVE-2022-38041 DoS 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Secure Channel Denial of Service Vulnerability.
12 CVE-2022-38040 Exec Code 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Microsoft ODBC Driver Remote Code Execution Vulnerability.
13 CVE-2022-38039 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37988, CVE-2022-37990, CVE-2022-37991, CVE-2022-37995, CVE-2022-38022, CVE-2022-38037, CVE-2022-38038.
14 CVE-2022-38038 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37988, CVE-2022-37990, CVE-2022-37991, CVE-2022-37995, CVE-2022-38022, CVE-2022-38037, CVE-2022-38039.
15 CVE-2022-38037 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37988, CVE-2022-37990, CVE-2022-37991, CVE-2022-37995, CVE-2022-38022, CVE-2022-38038, CVE-2022-38039.
16 CVE-2022-38036 DoS 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability.
17 CVE-2022-38034 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Workstation Service Elevation of Privilege Vulnerability.
18 CVE-2022-38033 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability.
19 CVE-2022-38032 Bypass 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability.
20 CVE-2022-38031 Exec Code 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-37982.
21 CVE-2022-38030 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows USB Serial Driver Information Disclosure Vulnerability.
22 CVE-2022-38029 362 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows ALPC Elevation of Privilege Vulnerability.
23 CVE-2022-38028 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Print Spooler Elevation of Privilege Vulnerability.
24 CVE-2022-38027 362 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Storage Elevation of Privilege Vulnerability.
25 CVE-2022-38026 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows DHCP Client Information Disclosure Vulnerability.
26 CVE-2022-38025 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Distributed File System (DFS) Information Disclosure Vulnerability.
27 CVE-2022-38022 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37988, CVE-2022-37990, CVE-2022-37991, CVE-2022-37995, CVE-2022-38037, CVE-2022-38038, CVE-2022-38039.
28 CVE-2022-38021 362 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Connected User Experiences and Telemetry Elevation of Privilege Vulnerability.
29 CVE-2022-38016 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability.
30 CVE-2022-38006 668 2022-09-13 2022-09-16

0.0

None ??? ??? ??? ??? ??? ???
Windows Graphics Component Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022-34728, CVE-2022-35837.
31 CVE-2022-38005 2022-09-13 2022-09-16

0.0

None ??? ??? ??? ??? ??? ???
Windows Print Spooler Elevation of Privilege Vulnerability.
32 CVE-2022-38004 Exec Code 2022-09-13 2022-09-16

0.0

None ??? ??? ??? ??? ??? ???
Windows Fax Service Remote Code Execution Vulnerability.
33 CVE-2022-38003 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Resilient File System Elevation of Privilege.
34 CVE-2022-38000 362 Exec Code 2022-10-11 2022-10-13

0.0

None ??? ??? ??? ??? ??? ???
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22035, CVE-2022-24504, CVE-2022-30198, CVE-2022-33634, CVE-2022-38047, CVE-2022-41081.
35 CVE-2022-37999 2022-10-11 2022-10-13

0.0

None ??? ??? ??? ??? ??? ???
Windows Group Policy Preference Client Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37993, CVE-2022-37994.
36 CVE-2022-37998 DoS 2022-10-11 2022-10-13

0.0

None ??? ??? ??? ??? ??? ???
Windows Local Session Manager (LSM) Denial of Service Vulnerability. This CVE ID is unique from CVE-2022-37973.
37 CVE-2022-37997 2022-10-11 2022-10-13

0.0

None ??? ??? ??? ??? ??? ???
Windows Graphics Component Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-38051.
38 CVE-2022-37996 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Kernel Memory Information Disclosure Vulnerability.
39 CVE-2022-37995 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37988, CVE-2022-37990, CVE-2022-37991, CVE-2022-38022, CVE-2022-38037, CVE-2022-38038, CVE-2022-38039.
40 CVE-2022-37994 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Group Policy Preference Client Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37993, CVE-2022-37999.
41 CVE-2022-37993 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Group Policy Preference Client Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37994, CVE-2022-37999.
42 CVE-2022-37991 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37988, CVE-2022-37990, CVE-2022-37995, CVE-2022-38022, CVE-2022-38037, CVE-2022-38038, CVE-2022-38039.
43 CVE-2022-37990 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37988, CVE-2022-37991, CVE-2022-37995, CVE-2022-38022, CVE-2022-38037, CVE-2022-38038, CVE-2022-38039.
44 CVE-2022-37989 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37987.
45 CVE-2022-37988 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37990, CVE-2022-37991, CVE-2022-37995, CVE-2022-38022, CVE-2022-38037, CVE-2022-38038, CVE-2022-38039.
46 CVE-2022-37987 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37989.
47 CVE-2022-37986 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Win32k Elevation of Privilege Vulnerability.
48 CVE-2022-37985 668 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows Graphics Component Information Disclosure Vulnerability.
49 CVE-2022-37984 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Windows WLAN Service Elevation of Privilege Vulnerability.
50 CVE-2022-37983 2022-10-11 2022-10-12

0.0

None ??? ??? ??? ??? ??? ???
Microsoft DWM Core Library Elevation of Privilege Vulnerability.

Total number of vulnerabilities : 510   Page : 1 (This Page)2 3 4 5 6 7 8 9 10 11

Is Windows 11 secure to use?

Window 11 uses virtualization-based security (VBS) for enhanced kernel protection against potential threats. Hypervisor-protected code integrity (HVCI), also called memory integrity, will be enabled by default on all new Windows 11 devices.

Can Windows 11 be hacked?

Hackers can use Microsoft's Power Automate to push out ransomware and key loggers—if they get machine access first.

Does Windows 11 have any problems?

Intel and Microsoft have found incompatibility issues with certain versions of drivers for Intel Smart Sound Technology (Intel SST) on Intel 11th Gen Core processors and Windows 11. Windows 11 devices with the affected Intel SST driver might receive an error with a blue screen.

Is it safe to update to Windows 11?

But if you're still hesitant, there's really no reason why you should upgrade to Windows 11 right away. As long as you're on Windows 10, you'll have access to many of Windows 11's key features (like Auto HDR and virtual desktops) as well as critical updates and security patches through 2025.