Windows
by Microsoft
CVEs (2,653)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-20697 | Hig | 0.53 | 7.3 | 0.72 | Jan 9, 2024 | Windows libarchive Remote Code Execution Vulnerability | ||
| CVE-2022-41091 | Med | 0.53 | 5.4 | 0.02 | KEV | Nov 9, 2022 | Windows Mark of the Web Security Feature Bypass Vulnerability | |
| CVE-2022-33679 | Hig | 0.53 | 8.1 | 0.09 | Sep 13, 2022 | Windows Kerberos Elevation of Privilege Vulnerability | ||
| CVE-2022-33647 | Hig | 0.53 | 8.1 | 0.02 | Sep 13, 2022 | Windows Kerberos Elevation of Privilege Vulnerability | ||
| CVE-2022-24545 | Hig | 0.53 | 8.1 | 0.02 | Apr 15, 2022 | Windows Kerberos Remote Code Execution Vulnerability | ||
| CVE-2021-36958 | Hig | 0.53 | 7.8 | 0.31 | Aug 12, 2021 | A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs;… | ||
| CVE-2021-34492 | Hig | 0.53 | 8.1 | 0.02 | Jul 14, 2021 | Windows Certificate Spoofing Vulnerability | ||
| CVE-2021-24086 | Hig | 0.53 | 7.5 | 0.59 | Feb 25, 2021 | Windows TCP/IP Denial of Service Vulnerability | ||
| CVE-2020-1400 | Hig | 0.53 | 7.8 | 0.24 | Jul 14, 2020 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1401, CVE-2020-1407. | ||
| CVE-2020-0665 | Hig | 0.53 | 8.1 | 0.04 | Feb 11, 2020 | An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privilege Vulnerability'. | ||
| CVE-2019-1424 | Hig | 0.53 | 8.1 | 0.03 | Nov 12, 2019 | A security feature bypass vulnerability exists when Windows Netlogon improperly handles a secure communications channel, aka 'NetLogon Security Feature Bypass Vulnerability'. | ||
| CVE-2019-1311 | Hig | 0.53 | 7.8 | 0.36 | Oct 10, 2019 | A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects in memory, aka 'Windows Imaging API Remote Code Execution Vulnerability'. | ||
| CVE-2019-0734 | Hig | 0.53 | 8.1 | 0.04 | May 16, 2019 | An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully decode and replace authentication request using Kerberos, allowing an attacker to be validated as an Administrator.The update addresses this… | ||
| CVE-2018-8210 | Hig | 0.53 | 7.8 | 0.25 | Jun 14, 2018 | A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka "Windows Remote Code Execution Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2016, Windows 8.1, Windows 10, Windows 10… | ||
| CVE-2017-11812 | Hig | 0.53 | 7.5 | 0.47 | Oct 13, 2017 | ChakraCore and Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption… | ||
| CVE-2017-0166 | Hig | 0.53 | 8.1 | 0.06 | Apr 12, 2017 | An elevation of privilege vulnerability exists in Windows when LDAP request buffer lengths are improperly calculated. In a remote attack scenario, an attacker could exploit this vulnerability by running a specially crafted application to send malicious traffic to a Domain… | ||
| CVE-2016-3396 | Hig | 0.53 | 7.8 | 0.24 | Oct 14, 2016 | Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for… | ||
| CVE-2016-3237 | Hig | 0.53 | 7.5 | 0.17 | Aug 9, 2016 | Kerberos in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows man-in-the-middle attackers to bypass authentication via vectors related to a… | ||
| CVE-2016-0091 | Hig | 0.53 | 7.8 | 0.24 | Mar 9, 2016 | OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted file, aka "Windows OLE Memory Remote… | ||
| CVE-2013-3129 | Hig | 0.53 | 7.8 | 0.32 | Jul 10, 2013 | Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,… |
- risk 0.53cvss 7.3epss 0.72
Windows libarchive Remote Code Execution Vulnerability
- risk 0.53cvss 5.4epss 0.02
Windows Mark of the Web Security Feature Bypass Vulnerability
- risk 0.53cvss 8.1epss 0.09
Windows Kerberos Elevation of Privilege Vulnerability
- risk 0.53cvss 8.1epss 0.02
Windows Kerberos Elevation of Privilege Vulnerability
- risk 0.53cvss 8.1epss 0.02
Windows Kerberos Remote Code Execution Vulnerability
- risk 0.53cvss 7.8epss 0.31
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs;…
- risk 0.53cvss 8.1epss 0.02
Windows Certificate Spoofing Vulnerability
- risk 0.53cvss 7.5epss 0.59
Windows TCP/IP Denial of Service Vulnerability
- risk 0.53cvss 7.8epss 0.24
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1401, CVE-2020-1407.
- risk 0.53cvss 8.1epss 0.04
An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privilege Vulnerability'.
- risk 0.53cvss 8.1epss 0.03
A security feature bypass vulnerability exists when Windows Netlogon improperly handles a secure communications channel, aka 'NetLogon Security Feature Bypass Vulnerability'.
- risk 0.53cvss 7.8epss 0.36
A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects in memory, aka 'Windows Imaging API Remote Code Execution Vulnerability'.
- risk 0.53cvss 8.1epss 0.04
An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully decode and replace authentication request using Kerberos, allowing an attacker to be validated as an Administrator.The update addresses this…
- risk 0.53cvss 7.8epss 0.25
A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka "Windows Remote Code Execution Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2016, Windows 8.1, Windows 10, Windows 10…
- risk 0.53cvss 7.5epss 0.47
ChakraCore and Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption…
- risk 0.53cvss 8.1epss 0.06
An elevation of privilege vulnerability exists in Windows when LDAP request buffer lengths are improperly calculated. In a remote attack scenario, an attacker could exploit this vulnerability by running a specially crafted application to send malicious traffic to a Domain…
- risk 0.53cvss 7.8epss 0.24
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for…
- risk 0.53cvss 7.5epss 0.17
Kerberos in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows man-in-the-middle attackers to bypass authentication via vectors related to a…
- risk 0.53cvss 7.8epss 0.24
OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted file, aka "Windows OLE Memory Remote…
- risk 0.53cvss 7.8epss 0.32
Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,…
Page 20 of 133