Win32K
by Microsoft
CVEs (154)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-1469 | Med | 0.36 | 5.5 | 0.02 | Dec 10, 2019 | An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. | ||
| CVE-2019-1440 | Med | 0.36 | 5.5 | 0.02 | Nov 12, 2019 | An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1436. | ||
| CVE-2019-1436 | Med | 0.36 | 5.5 | 0.02 | Nov 12, 2019 | An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1440. | ||
| CVE-2019-1096 | Med | 0.36 | 5.5 | 0.06 | Jul 15, 2019 | An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. | ||
| CVE-2019-0848 | Med | 0.36 | 5.5 | 0.03 | Apr 9, 2019 | An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0814. | ||
| CVE-2019-0814 | Med | 0.36 | 5.5 | 0.03 | Apr 9, 2019 | An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0848. | ||
| CVE-2019-0776 | Med | 0.36 | 5.5 | 0.03 | Apr 9, 2019 | An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. | ||
| CVE-2019-0628 | Med | 0.36 | 5.5 | 0.03 | Mar 5, 2019 | An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. | ||
| CVE-2018-8565 | Med | 0.36 | 5.5 | 0.03 | Nov 14, 2018 | An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka "Win32k Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows… | ||
| CVE-2026-69792 | Med | 0.31 | 4.7 | 0.00 | Sep 8, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2013-3661 | 0.03 | — | 0.04 | May 24, 2013 | The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether linked-list traversal is… | |||
| CVE-2011-1873 | 0.01 | — | 0.19 | Jun 16, 2011 | win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 on 64-bit platforms does not properly validate pointers during the parsing of OpenType… | |||
| CVE-2026-57095 | Med | 0.00 | 6.2 | 0.00 | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-56184 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. | ||
| CVE-2026-50687 | Hig | 0.00 | 8.8 | 0.00 | Jul 14, 2026 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50670 | Hig | 0.00 | 8.8 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50489 | Hig | 0.00 | 8.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50416 | Low | 0.00 | 3.3 | 0.00 | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. | ||
| CVE-2026-54986 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-54114 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
- risk 0.36cvss 5.5epss 0.02
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.
- risk 0.36cvss 5.5epss 0.02
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1436.
- risk 0.36cvss 5.5epss 0.02
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1440.
- risk 0.36cvss 5.5epss 0.06
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.
- risk 0.36cvss 5.5epss 0.03
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0814.
- risk 0.36cvss 5.5epss 0.03
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0848.
- risk 0.36cvss 5.5epss 0.03
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.
- risk 0.36cvss 5.5epss 0.03
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.
- risk 0.36cvss 5.5epss 0.03
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka "Win32k Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows…
- risk 0.31cvss 4.7epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to bypass a security feature locally.
- CVE-2013-3661May 24, 2013risk 0.03cvss —epss 0.04
The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether linked-list traversal is…
- CVE-2011-1873Jun 16, 2011risk 0.01cvss —epss 0.19
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 on 64-bit platforms does not properly validate pointers during the parsing of OpenType…
- risk 0.00cvss 6.2epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.
- risk 0.00cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.
- risk 0.00cvss 8.8epss 0.00
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 8.8epss 0.00
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 8.8epss 0.00
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 3.3epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.
- risk 0.00cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Page 7 of 8