Windows Kernel
by Microsoft
CVEs (421)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-50390 | Hig | 0.00 | 7.0 | 0.00 | Jul 14, 2026 | Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50377 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50332 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50329 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-58614 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2026-54132 | Med | 0.00 | 6.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. | ||
| CVE-2026-50354 | Hig | 0.00 | 7.1 | 0.00 | Jul 14, 2026 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50316 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2026-50300 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2026-50294 | Med | 0.00 | 6.2 | 0.01 | Jul 14, 2026 | Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-49808 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-49798 | Cri | 0.00 | 9.3 | 0.00 | Jul 14, 2026 | Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-49795 | Hig | 0.00 | 8.8 | 0.00 | Jul 14, 2026 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-49173 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-49167 | Med | 0.00 | 4.7 | 0.00 | Jul 14, 2026 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2013-3136 | 0.00 | — | 0.02 | Jun 12, 2013 | The kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly handle unspecified page-fault system calls, which allows local users to obtain sensitive information… | |||
| CVE-2013-1280 | 0.00 | — | 0.02 | Feb 13, 2013 | The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to… | |||
| CVE-2008-2251 | 0.00 | — | 0.01 | Oct 15, 2008 | Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that makes system calls within multiple threads, aka "Windows… | |||
| CVE-2008-2250 | 0.00 | — | 0.02 | Oct 15, 2008 | The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate window properties sent from a parent window to a child window during creation of a new window, which allows local users to gain… | |||
| CVE-2004-0893 | 0.00 | — | 0.02 | Jan 10, 2005 | The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel… |
- risk 0.00cvss 7.0epss 0.00
Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 5.5epss 0.00
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 5.5epss 0.00
Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.
- risk 0.00cvss 6.8epss 0.00
Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.
- risk 0.00cvss 7.1epss 0.00
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 5.5epss 0.00
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.00
Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.00cvss 6.2epss 0.01
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 7.8epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 9.3epss 0.00
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
- risk 0.00cvss 8.8epss 0.00
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 4.7epss 0.00
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2013-3136Jun 12, 2013risk 0.00cvss —epss 0.02
The kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly handle unspecified page-fault system calls, which allows local users to obtain sensitive information…
- CVE-2013-1280Feb 13, 2013risk 0.00cvss —epss 0.02
The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to…
- CVE-2008-2251Oct 15, 2008risk 0.00cvss —epss 0.01
Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that makes system calls within multiple threads, aka "Windows…
- CVE-2008-2250Oct 15, 2008risk 0.00cvss —epss 0.02
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate window properties sent from a parent window to a child window during creation of a new window, which allows local users to gain…
- CVE-2004-0893Jan 10, 2005risk 0.00cvss —epss 0.02
The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel…
Page 21 of 22