Windows OLE
by Microsoft
CVEs (10)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-21298 | Cri | 0.70 | 9.8 | 0.81 | Jan 14, 2025 | Windows OLE Remote Code Execution Vulnerability | ||
| CVE-2017-8487 | Hig | 0.59 | 7.8 | 0.54 | Jun 15, 2017 | Windows OLE in Windows XP and Windows Server 2003 allows an attacker to execute code when a victim opens a specially crafted file or program aka "Windows olecnv32.dll Remote Code Execution Vulnerability." | ||
| CVE-2020-1281 | Hig | 0.58 | 8.8 | 0.14 | Jun 9, 2020 | A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'. | ||
| CVE-2024-21372 | Hig | 0.57 | 8.8 | 0.02 | Feb 13, 2024 | Windows OLE Remote Code Execution Vulnerability | ||
| CVE-2026-26162 | Hig | 0.51 | 7.8 | 0.00 | Apr 14, 2026 | Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-60714 | Hig | 0.51 | 7.8 | 0.01 | Nov 11, 2025 | Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally. | ||
| CVE-2024-38152 | Hig | 0.51 | 7.8 | 0.01 | Aug 13, 2024 | Windows OLE Remote Code Execution Vulnerability | ||
| CVE-2023-35323 | Hig | 0.51 | 7.8 | 0.01 | Jul 11, 2023 | Windows OLE Remote Code Execution Vulnerability | ||
| CVE-2019-1484 | Hig | 0.51 | 7.8 | 0.09 | Dec 10, 2019 | A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'. | ||
| CVE-2017-0211 | Med | 0.40 | 5.5 | 0.14 | Apr 12, 2017 | An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 versions of Microsoft Windows OLE when it fails an integrity-level check, aka "Windows OLE Elevation of Privilege… |
- risk 0.70cvss 9.8epss 0.81
Windows OLE Remote Code Execution Vulnerability
- risk 0.59cvss 7.8epss 0.54
Windows OLE in Windows XP and Windows Server 2003 allows an attacker to execute code when a victim opens a specially crafted file or program aka "Windows olecnv32.dll Remote Code Execution Vulnerability."
- risk 0.58cvss 8.8epss 0.14
A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.
- risk 0.57cvss 8.8epss 0.02
Windows OLE Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.01
Windows OLE Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows OLE Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.09
A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.
- risk 0.40cvss 5.5epss 0.14
An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 versions of Microsoft Windows OLE when it fails an integrity-level check, aka "Windows OLE Elevation of Privilege…