Windows Management Instrumentation
by Microsoft
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-77905 | Hig | 0.46 | 7.0 | 0.00 | Sep 8, 2026 | Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69451 | Hig | 0.46 | 7.1 | 0.01 | Sep 8, 2026 | Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-70582 | Med | 0.42 | 6.4 | 0.00 | Sep 8, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69349 | Med | 0.37 | 5.7 | 0.01 | Sep 8, 2026 | Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-62738 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally. | ||
| CVE-2009-0078 | 0.03 | — | 0.03 | Apr 15, 2009 | The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or… | |||
| CVE-2005-1792 | 0.01 | — | 0.07 | Jun 1, 2005 | Memory leak in Windows Management Instrumentation (WMI) service allows attackers to cause a denial of service (memory consumption and crash) by creating security contexts more quickly than they can be cleared from the RPC cache. |
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.1epss 0.01
Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges over a network.
- risk 0.42cvss 6.4epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.
- CVE-2009-0078Apr 15, 2009risk 0.03cvss —epss 0.03
The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or…
- CVE-2005-1792Jun 1, 2005risk 0.01cvss —epss 0.07
Memory leak in Windows Management Instrumentation (WMI) service allows attackers to cause a denial of service (memory consumption and crash) by creating security contexts more quickly than they can be cleared from the RPC cache.