Windows
by Microsoft
CVEs (2,653)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-0108 | Hig | 0.58 | 7.8 | 0.59 | Mar 17, 2017 | The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows remote attackers to… | ||
| CVE-2016-3304 | Hig | 0.58 | 7.8 | 0.42 | Aug 9, 2016 | The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, Lync 2013 SP1, Lync 2010, Lync 2010 Attendee, and Live Meeting 2007 Console allows remote attackers… | ||
| CVE-2016-3303 | Hig | 0.58 | 7.8 | 0.42 | Aug 9, 2016 | The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, Lync 2013 SP1, Lync 2010, Lync 2010 Attendee, and Live Meeting 2007 Console allows remote attackers… | ||
| CVE-2016-0015 | Hig | 0.58 | 7.8 | 0.35 | Jan 13, 2016 | DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted file, aka "DirectShow Heap… | ||
| CVE-2016-0009 | Hig | 0.58 | 8.8 | 0.14 | Jan 13, 2016 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows 10 Gold and 1511 allow remote attackers to execute arbitrary code via unspecified vectors, aka "Win32k Remote Code Execution Vulnerability." | ||
| CVE-2011-1265 | Hig | 0.58 | 8.8 | 0.06 | Jul 13, 2011 | The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that (1) were not properly initialized or (2) have been deleted, which allows remote attackers to execute arbitrary code via crafted Bluetooth… | ||
| CVE-2010-0820 | Hig | 0.58 | 8.8 | 0.14 | Sep 15, 2010 | Heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS), as used in Active Directory in Microsoft Windows Server 2003 SP2 and Windows Server 2008 Gold, SP2, and R2; Active Directory Application Mode (ADAM) in Windows XP SP2 and SP3 and Windows Server… | ||
| CVE-2024-21435 | Hig | 0.57 | 8.8 | 0.02 | Mar 12, 2024 | Windows OLE Remote Code Execution Vulnerability | ||
| CVE-2022-24487 | Hig | 0.57 | 8.8 | 0.02 | Apr 15, 2022 | Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability | ||
| CVE-2022-21920 | Hig | 0.57 | 8.8 | 0.03 | Jan 11, 2022 | Windows Kerberos Elevation of Privilege Vulnerability | ||
| CVE-2021-42275 | Hig | 0.57 | 8.8 | 0.02 | Nov 10, 2021 | Microsoft COM for Windows Remote Code Execution Vulnerability | ||
| CVE-2021-36970 | Hig | 0.57 | 8.8 | 0.03 | Oct 13, 2021 | Windows Print Spooler Spoofing Vulnerability | ||
| CVE-2021-24088 | Hig | 0.57 | 8.8 | 0.02 | Feb 25, 2021 | Windows Local Spooler Remote Code Execution Vulnerability | ||
| CVE-2020-17162 | Hig | 0.57 | 8.8 | 0.02 | Feb 25, 2021 | Microsoft Windows Security Feature Bypass Vulnerability | ||
| CVE-2020-1255 | Hig | 0.57 | 8.8 | 0.03 | Jun 9, 2020 | An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'. | ||
| CVE-2020-1118 | Hig | 0.57 | 8.6 | 0.16 | May 21, 2020 | A denial of service vulnerability exists in the Windows implementation of Transport Layer Security (TLS) when it improperly handles certain key exchanges. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this… | ||
| CVE-2020-0981 | Hig | 0.57 | 8.8 | 0.01 | Apr 15, 2020 | A security feature bypass vulnerability exists when Windows fails to properly handle token relationships.An attacker who successfully exploited the vulnerability could allow an application with a certain integrity level to execute code at a different integrity level, leading to… | ||
| CVE-2020-0655 | Hig | 0.57 | 8.0 | 0.66 | Feb 11, 2020 | A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'. | ||
| CVE-2019-1358 | Hig | 0.57 | 7.8 | 0.78 | Oct 10, 2019 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1359. | ||
| CVE-2017-11907 | Hig | 0.57 | 7.5 | 0.50 | Dec 12, 2017 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to… |
- risk 0.58cvss 7.8epss 0.59
The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows remote attackers to…
- risk 0.58cvss 7.8epss 0.42
The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, Lync 2013 SP1, Lync 2010, Lync 2010 Attendee, and Live Meeting 2007 Console allows remote attackers…
- risk 0.58cvss 7.8epss 0.42
The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, Lync 2013 SP1, Lync 2010, Lync 2010 Attendee, and Live Meeting 2007 Console allows remote attackers…
- risk 0.58cvss 7.8epss 0.35
DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted file, aka "DirectShow Heap…
- risk 0.58cvss 8.8epss 0.14
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows 10 Gold and 1511 allow remote attackers to execute arbitrary code via unspecified vectors, aka "Win32k Remote Code Execution Vulnerability."
- risk 0.58cvss 8.8epss 0.06
The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that (1) were not properly initialized or (2) have been deleted, which allows remote attackers to execute arbitrary code via crafted Bluetooth…
- risk 0.58cvss 8.8epss 0.14
Heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS), as used in Active Directory in Microsoft Windows Server 2003 SP2 and Windows Server 2008 Gold, SP2, and R2; Active Directory Application Mode (ADAM) in Windows XP SP2 and SP3 and Windows Server…
- risk 0.57cvss 8.8epss 0.02
Windows OLE Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.03
Windows Kerberos Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft COM for Windows Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.03
Windows Print Spooler Spoofing Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Local Spooler Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft Windows Security Feature Bypass Vulnerability
- risk 0.57cvss 8.8epss 0.03
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
- risk 0.57cvss 8.6epss 0.16
A denial of service vulnerability exists in the Windows implementation of Transport Layer Security (TLS) when it improperly handles certain key exchanges. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this…
- risk 0.57cvss 8.8epss 0.01
A security feature bypass vulnerability exists when Windows fails to properly handle token relationships.An attacker who successfully exploited the vulnerability could allow an application with a certain integrity level to execute code at a different integrity level, leading to…
- risk 0.57cvss 8.0epss 0.66
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
- risk 0.57cvss 7.8epss 0.78
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1359.
- risk 0.57cvss 7.5epss 0.50
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to…
Page 14 of 133