cbcvebase.

Microsoft Windows vulnerabilities

424 known vulnerabilities affecting microsoft/windows.

Total CVEs
424
CISA KEV
21
actively exploited
Public exploits
27
Exploited in wild
28
Severity breakdown
CRITICAL11HIGH275MEDIUM136LOW2

Vulnerabilities

Page 10 of 22
CVE-2020-1354P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-07-14
CVE-2020-1354 [HIGH] CVE-2020-1354: An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows UPnP Device Host Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1430.
nvd
CVE-2020-0793P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+11 more2020-03-12
CVE-2020-0793 [HIGH] CVE-2020-0793: An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service i An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0701P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+7 more2020-02-11
CVE-2020-0701 [HIGH] CVE-2020-0701: An elevation of privilege vulnerability exists in the way that the Windows Client License Service (C An elevation of privilege vulnerability exists in the way that the Windows Client License Service (ClipSVC) handles objects in memory, aka 'Windows Client License Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1347P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+7 more2020-07-14
CVE-2020-1347 [HIGH] CVE-2020-1347: An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle f An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle file operations, aka 'Windows Storage Services Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1379P3HIGHCVSS 7.8v10 for 32-bit Systemsv10 for x64-based Systems+11 more2019-11-12
CVE-2019-1379 [HIGH] CVE-2019-1379: An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly hand An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka 'Windows Data Sharing Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1383, CVE-2019-1417.
nvd
CVE-2020-1396P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-07-14
CVE-2020-1396 [HIGH] CVE-2020-1396: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Loc An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system, aka 'Windows ALPC Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0808P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+7 more2020-03-12
CVE-2020-0808 [HIGH] CWE-20 CVE-2020-0808: An elevation of privilege vulnerability exists in the way the Provisioning Runtime validates certain An elevation of privilege vulnerability exists in the way the Provisioning Runtime validates certain file operations, aka 'Provisioning Runtime Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0620P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-01-14
CVE-2020-0620 [HIGH] CVE-2020-0620: An elevation of privilege vulnerability exists when Microsoft Cryptographic Services improperly hand An elevation of privilege vulnerability exists when Microsoft Cryptographic Services improperly handles files, aka 'Microsoft Cryptographic Services Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1363P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+7 more2020-07-14
CVE-2020-1363 [HIGH] CVE-2020-1363: An elevation of privilege vulnerability exists when the Windows Picker Platform improperly handles m An elevation of privilege vulnerability exists when the Windows Picker Platform improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Picker Platform Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1352P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+11 more2020-07-14
CVE-2020-1352 [HIGH] CVE-2020-1352: An elevation of privilege vulnerability exists when the Windows USO Core Worker improperly handles m An elevation of privilege vulnerability exists when the Windows USO Core Worker improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows USO Core Worker Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1372P3HIGHCVSS 7.8v10 Version 1809 for 32-bit Systemsv10 Version 1809 for x64-based Systems+1 more2020-07-14
CVE-2020-1372 [HIGH] CVE-2020-1372: An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnosti An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles objects in memory, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1405.
nvd
CVE-2019-1235P3HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-09-11
CVE-2019-1235 [HIGH] CWE-346 CVE-2019-1235: An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server process does not validate the source of input or commands it receives, aka 'Windows Text Service Framework Elevation of Privilege Vulnerability'.
nvd
CVE-2025-59033P3HIGHCVSS 7.4≥ 10, ≤ Server 20252025-09-08
CVE-2025-59033 [HIGH] CWE-420 CVE-2025-59033: The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (W The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code signer certificate are properly blocked, but entries that specify the signing certificate's TBS hash along with a 'FileAttribRef' qualifier (such as file name or version) may
nvd
CVE-2020-1217P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+7 more2020-06-09
CVE-2020-1217 [HIGH] CVE-2020-1217: An information disclosure vulnerability exists when the Windows Runtime improperly handles objects i An information disclosure vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Information Disclosure Vulnerability'.
nvd
CVE-2020-1231P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+14 more2020-06-09
CVE-2020-1231 [HIGH] CVE-2020-1231: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects i An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE-2020-1282, CVE-2020-1304, CVE-2020-1306, CVE-2020-1334.
nvd
CVE-2020-1287P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1709 for x64-based Systems+11 more2020-06-09
CVE-2020-1287 [HIGH] CVE-2020-1287: An elevation of privilege vulnerability exists in the way that the Windows WalletService handles obj An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletService Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1294.
nvd
CVE-2019-0838P3HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-04-09
CVE-2019-0838 [HIGH] CVE-2019-0838: An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses cred An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses credentials to Windows Credential Manager, aka 'Windows Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0839.
nvd
CVE-2019-1393P3HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+5 more2019-11-12
CVE-2019-1393 [HIGH] CWE-787 CVE-2019-1393: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1394, CVE-2019-1395, CVE-2019-1396, CVE-2019-1408, CVE-2019-1434.
nvd
CVE-2020-0791P3HIGHCVSS 7.8v10 Version 1607 for 32-bit Systemsv10 Version 1607 for x64-based Systems2020-03-12
CVE-2020-0791 [HIGH] CVE-2020-0791: An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handle An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0898.
nvd
CVE-2019-1341P3HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-10-10
CVE-2019-1341 [HIGH] CVE-2019-1341: An elevation of privilege vulnerability exists when umpo.dll of the Power Service, improperly handle An elevation of privilege vulnerability exists when umpo.dll of the Power Service, improperly handles a Registry Restore Key function, aka 'Windows Power Service Elevation of Privilege Vulnerability'.
nvd