Windows
by Microsoft
CVEs (2,653)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-40476 | Hig | 0.49 | 7.5 | 0.02 | Oct 13, 2021 | Windows AppContainer Elevation Of Privilege Vulnerability | ||
| CVE-2021-36953 | Hig | 0.49 | 7.5 | 0.05 | Oct 13, 2021 | Windows TCP/IP Denial of Service Vulnerability | ||
| CVE-2021-36960 | Hig | 0.49 | 7.5 | 0.03 | Sep 15, 2021 | Windows SMB Information Disclosure Vulnerability | ||
| CVE-2021-36933 | Hig | 0.49 | 7.5 | 0.03 | Aug 12, 2021 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | ||
| CVE-2021-36926 | Hig | 0.49 | 7.5 | 0.03 | Aug 12, 2021 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | ||
| CVE-2021-31958 | Hig | 0.49 | 7.5 | 0.03 | Jun 8, 2021 | Windows NTLM Elevation of Privilege Vulnerability | ||
| CVE-2021-28319 | Hig | 0.49 | 7.5 | 0.09 | Apr 13, 2021 | Windows TCP/IP Driver Denial of Service Vulnerability | ||
| CVE-2021-26879 | Hig | 0.49 | 7.5 | 0.04 | Mar 11, 2021 | Windows Network Address Translation (NAT) Denial of Service Vulnerability | ||
| CVE-2021-1734 | Hig | 0.49 | 7.5 | 0.04 | Feb 25, 2021 | Windows Remote Procedure Call Information Disclosure Vulnerability | ||
| CVE-2020-1013 | Hig | 0.49 | 7.5 | 0.06 | Sep 11, 2020 | An elevation of privilege vulnerability exists when Microsoft Windows processes group policy updates. An attacker who successfully exploited this vulnerability could potentially escalate permissions or perform additional privileged actions on the target machine. To… | ||
| CVE-2020-1565 | Hig | 0.49 | 7.5 | 0.03 | Aug 17, 2020 | An elevation of privilege vulnerability exists when the "Public Account Pictures" folder improperly handles junctions. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted… | ||
| CVE-2020-1374 | Hig | 0.49 | 7.5 | 0.08 | Jul 14, 2020 | A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. | ||
| CVE-2020-0909 | Hig | 0.49 | 7.5 | 0.05 | May 21, 2020 | A denial of service vulnerability exists when Hyper-V on a Windows Server fails to properly handle specially crafted network packets. To exploit the vulnerability, an attacker would send specially crafted network packets to the Hyper-V Server. The security update addresses the… | ||
| CVE-2020-0645 | Hig | 0.49 | 7.5 | 0.04 | Mar 12, 2020 | A tampering vulnerability exists when Microsoft IIS Server improperly handles malformed request headers, aka 'Microsoft IIS Server Tampering Vulnerability'. | ||
| CVE-2020-0660 | Hig | 0.49 | 7.5 | 0.05 | Feb 11, 2020 | A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'. | ||
| CVE-2020-0611 | Hig | 0.49 | 7.5 | 0.08 | Jan 14, 2020 | A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. | ||
| CVE-2019-1453 | Hig | 0.49 | 7.5 | 0.09 | Dec 10, 2019 | A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'. | ||
| CVE-2019-1326 | Hig | 0.49 | 7.5 | 0.06 | Oct 10, 2019 | A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'. | ||
| CVE-2019-1188 | Hig | 0.49 | 7.5 | 0.04 | Aug 14, 2019 | A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured… | ||
| CVE-2019-1006 | Hig | 0.49 | 7.5 | 0.06 | Jul 15, 2019 | An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'. |
- risk 0.49cvss 7.5epss 0.02
Windows AppContainer Elevation Of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.05
Windows TCP/IP Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows SMB Information Disclosure Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows NTLM Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.09
Windows TCP/IP Driver Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.04
Windows Network Address Translation (NAT) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.04
Windows Remote Procedure Call Information Disclosure Vulnerability
- risk 0.49cvss 7.5epss 0.06
An elevation of privilege vulnerability exists when Microsoft Windows processes group policy updates. An attacker who successfully exploited this vulnerability could potentially escalate permissions or perform additional privileged actions on the target machine. To…
- risk 0.49cvss 7.5epss 0.03
An elevation of privilege vulnerability exists when the "Public Account Pictures" folder improperly handles junctions. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted…
- risk 0.49cvss 7.5epss 0.08
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.
- risk 0.49cvss 7.5epss 0.05
A denial of service vulnerability exists when Hyper-V on a Windows Server fails to properly handle specially crafted network packets. To exploit the vulnerability, an attacker would send specially crafted network packets to the Hyper-V Server. The security update addresses the…
- risk 0.49cvss 7.5epss 0.04
A tampering vulnerability exists when Microsoft IIS Server improperly handles malformed request headers, aka 'Microsoft IIS Server Tampering Vulnerability'.
- risk 0.49cvss 7.5epss 0.05
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
- risk 0.49cvss 7.5epss 0.08
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.
- risk 0.49cvss 7.5epss 0.09
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
- risk 0.49cvss 7.5epss 0.06
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
- risk 0.49cvss 7.5epss 0.04
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured…
- risk 0.49cvss 7.5epss 0.06
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.
Page 57 of 133