Microsoft Windows vulnerabilities
424 known vulnerabilities affecting microsoft/windows.
Total CVEs
424
CISA KEV
21
actively exploited
Public exploits
27
Exploited in wild
28
Severity breakdown
CRITICAL11HIGH275MEDIUM136LOW2
Vulnerabilities
Page 11 of 22
CVE-2019-0892P3HIGHCVSS 7.8v10 Version 1709 for 32-bit Systemsv10 Version 1709 for x64-based Systems+7 more2019-05-16
CVE-2019-0892 [HIGH] CVE-2019-0892: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1316P3HIGHCVSS 7.8v10 for 32-bit Systemsv10 for x64-based Systems+13 more2019-10-10
CVE-2019-1316 [HIGH] CVE-2019-1316: An elevation of privilege vulnerability exists in Microsoft Windows Setup when it does not properly
An elevation of privilege vulnerability exists in Microsoft Windows Setup when it does not properly handle privileges, aka 'Microsoft Windows Setup Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0934P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-04-15
CVE-2020-0934 [HIGH] CVE-2020-0934: An elevation of privilege vulnerability exists when the Windows WpcDesktopMonSvc improperly manages
An elevation of privilege vulnerability exists when the Windows WpcDesktopMonSvc improperly manages memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0983, CVE-2020-1009, CVE-2020-1011, CVE-2020-1015.
nvd
CVE-2019-1477P3HIGHCVSS 7.8v10 Version 1809 for 32-bit Systemsv10 Version 1809 for x64-based Systems+1 more2019-12-10
CVE-2019-1477 [HIGH] CVE-2019-1477: An elevation of privilege vulnerability exists when the Windows Printer Service improperly validates
An elevation of privilege vulnerability exists when the Windows Printer Service improperly validates file paths while loading printer drivers, aka 'Windows Printer Service Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1256P3HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-09-11
CVE-2019-1256 [HIGH] CVE-2019-1256: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1285.
nvd
CVE-2019-0999P3HIGHCVSS 7.8v10 for 32-bit Systemsv10 for x64-based Systems+10 more2019-07-15
CVE-2019-0999 [HIGH] CVE-2019-0999: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, ak
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1323P3HIGHCVSS 7.8v10 Version 1809 for 32-bit Systemsv10 Version 1809 for x64-based Systems+1 more2019-10-10
CVE-2019-1323 [HIGH] CVE-2019-1323: An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does n
An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does not properly handle privileges, aka 'Microsoft Windows Update Client Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1336.
nvd
CVE-2019-1321P3HIGHCVSS 7.8v10 Version 1703 for 32-bit Systemsv10 Version 1703 for x64-based Systems+9 more2019-10-10
CVE-2019-1321 [HIGH] CVE-2019-1321: An elevation of privilege vulnerability exists when Windows CloudStore improperly handles file Discr
An elevation of privilege vulnerability exists when Windows CloudStore improperly handles file Discretionary Access Control List (DACL), aka 'Microsoft Windows CloudStore Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0784P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+7 more2020-04-15
CVE-2020-0784 [HIGH] CVE-2020-0784: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, ak
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0888.
nvd
CVE-2020-0691P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-02-11
CVE-2020-0691 [HIGH] CVE-2020-0691: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0719, CVE-2020-0720, CVE-2020-0721, CVE-2020-0722, CVE-2020-0723, CVE-2020-0724, CVE-2020-0725, CVE-2020-0726, CVE-2020-0731.
nvd
CVE-2020-0709P3HIGHCVSS 7.8v10 for 32-bit Systemsv10 for x64-based Systems+2 more2020-02-11
CVE-2020-0709 [HIGH] CVE-2020-0709: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, ak
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0732.
nvd
CVE-2020-0778P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-03-12
CVE-2020-0778 [HIGH] CVE-2020-0778: An elevation of privilege vulnerability exists in the way that the Windows Network Connections Servi
An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0802, CVE-2020-0803, CVE-2020-0804, CVE-2020-0845.
nvd
CVE-2020-0707P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+14 more2020-02-11
CVE-2020-0707 [HIGH] CVE-2020-0707: An elevation of privilege vulnerability exists when the Windows IME improperly handles memory.To exp
An elevation of privilege vulnerability exists when the Windows IME improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows IME Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0985P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+4 more2020-04-15
CVE-2020-0985 [HIGH] CVE-2020-0985: An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handl
An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0996.
nvd
CVE-2019-1271P3HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-09-11
CVE-2019-1271 [HIGH] CWE-787 CVE-2019-1271: An elevation of privilege exists in hdAudio.sys which may lead to an out of band write, aka 'Windows
An elevation of privilege exists in hdAudio.sys which may lead to an out of band write, aka 'Windows Media Elevation of Privilege Vulnerability'.
nvd
CVE-2019-0682P3HIGHCVSS 7.8v10 Version 1709 for 32-bit Systemsv10 Version 1709 for x64-based Systems+7 more2019-04-09
CVE-2019-0682 [HIGH] CWE-190 CVE-2019-0682: An elevation of privilege vulnerability exists due to an integer overflow in Windows Subsystem for L
An elevation of privilege vulnerability exists due to an integer overflow in Windows Subsystem for Linux, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0689, CVE-2019-0692, CVE-2019-0693, CVE-2019-0694.
nvd
CVE-2019-1284P3HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 12019-09-11
CVE-2019-1284 [HIGH] CVE-2019-1284: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, ak
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1202P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+11 more2020-06-09
CVE-2020-1202 [HIGH] CVE-2020-1202: An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Vi
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector fail to properly handle objects in memory, aka 'Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1203.
nvd
CVE-2020-1393P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+7 more2020-07-14
CVE-2020-1393 [HIGH] CVE-2020-1393: An elevation of privilege vulnerability exists when the Windows Diagnostics Hub Standard Collector S
An elevation of privilege vulnerability exists when the Windows Diagnostics Hub Standard Collector Service fails to properly sanitize input, leading to an unsecure library-loading behavior, aka 'Windows Diagnostics Hub Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1418.
nvd
CVE-2020-0956P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-04-15
CVE-2020-0956 [HIGH] CVE-2020-0956: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0957, CVE-2020-0958.
nvd