Win32K
by Microsoft
CVEs (148)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-0776 | Med | 0.36 | 5.5 | 0.02 | Apr 9, 2019 | An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. | ||
| CVE-2019-0628 | Med | 0.36 | 5.5 | 0.02 | Mar 5, 2019 | An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. | ||
| CVE-2018-8565 | Med | 0.36 | 5.5 | 0.03 | Nov 14, 2018 | An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka "Win32k Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows… | ||
| CVE-2013-3661 | 0.03 | — | 0.04 | May 24, 2013 | The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether linked-list traversal is… | |||
| CVE-2011-1873 | 0.01 | — | 0.19 | Jun 16, 2011 | win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 on 64-bit platforms does not properly validate pointers during the parsing of OpenType… | |||
| CVE-2026-57095 | Med | 0.00 | 6.2 | 0.00 | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-56184 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. | ||
| CVE-2026-56176 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50687 | Hig | 0.00 | 8.8 | 0.00 | Jul 14, 2026 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50670 | Hig | 0.00 | 8.8 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50489 | Hig | 0.00 | 8.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50416 | Low | 0.00 | 3.3 | 0.00 | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. | ||
| CVE-2026-54986 | Hig | 0.00 | 7.8 | 0.02 | Jul 14, 2026 | Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-54114 | Hig | 0.00 | 7.8 | 0.02 | Jul 14, 2026 | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-54107 | Hig | 0.00 | 8.8 | 0.00 | Jul 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50325 | Hig | 0.00 | 7.0 | 0.00 | Jul 14, 2026 | Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50297 | Hig | 0.00 | 7.0 | 0.00 | Jul 14, 2026 | Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-49805 | Hig | 0.00 | 7.0 | 0.03 | Jul 14, 2026 | Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||
| CVE-2015-2367 | 0.00 | — | 0.03 | Jul 14, 2015 | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain… | |||
| CVE-2013-3864 | 0.00 | — | 0.02 | Sep 11, 2013 | win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted… |
- risk 0.36cvss 5.5epss 0.02
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.
- risk 0.36cvss 5.5epss 0.02
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.
- risk 0.36cvss 5.5epss 0.03
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka "Win32k Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows…
- CVE-2013-3661May 24, 2013risk 0.03cvss —epss 0.04
The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether linked-list traversal is…
- CVE-2011-1873Jun 16, 2011risk 0.01cvss —epss 0.19
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 on 64-bit platforms does not properly validate pointers during the parsing of OpenType…
- risk 0.00cvss 6.2epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.
- risk 0.00cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.
- risk 0.00cvss 7.8epss 0.00
Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 8.8epss 0.00
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 8.8epss 0.00
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 8.8epss 0.00
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 3.3epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.
- risk 0.00cvss 7.8epss 0.02
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.02
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 8.8epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.0epss 0.00
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.0epss 0.00
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.0epss 0.03
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
- CVE-2015-2367Jul 14, 2015risk 0.00cvss —epss 0.03
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain…
- CVE-2013-3864Sep 11, 2013risk 0.00cvss —epss 0.02
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted…
Page 7 of 8