cbcvebase.

Microsoft Windows vulnerabilities

459 known vulnerabilities affecting microsoft/windows.

Total CVEs
459
CISA KEV
22
actively exploited
Public exploits
29
Exploited in wild
30
Severity breakdown
CRITICAL12HIGH301MEDIUM144LOW2

Vulnerabilities

Page 11 of 23
CVE-2020-1363P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+7 more2020-07-14
CVE-2020-1363 [HIGH] CVE-2020-1363: An elevation of privilege vulnerability exists when the Windows Picker Platform improperly handles m An elevation of privilege vulnerability exists when the Windows Picker Platform improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Picker Platform Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1352P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+11 more2020-07-14
CVE-2020-1352 [HIGH] CVE-2020-1352: An elevation of privilege vulnerability exists when the Windows USO Core Worker improperly handles m An elevation of privilege vulnerability exists when the Windows USO Core Worker improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows USO Core Worker Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1078P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-05-21
CVE-2020-1078 [HIGH] CVE-2020-1078: An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Insta An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1379P3HIGHCVSS 7.8v10 for 32-bit Systemsv10 for x64-based Systems+11 more2019-11-12
CVE-2019-1379 [HIGH] CVE-2019-1379: An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly hand An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka 'Windows Data Sharing Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1383, CVE-2019-1417.
nvd
CVE-2020-1372P3HIGHCVSS 7.8v10 Version 1809 for 32-bit Systemsv10 Version 1809 for x64-based Systems+1 more2020-07-14
CVE-2020-1372 [HIGH] CVE-2020-1372: An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnosti An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles objects in memory, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1405.
nvd
CVE-2020-1368P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+14 more2020-07-14
CVE-2020-1368 [HIGH] CVE-2020-1368: An elevation of privilege vulnerability exists in the way that the Credential Enrollment Manager ser An elevation of privilege vulnerability exists in the way that the Credential Enrollment Manager service handles objects in memory, aka 'Windows Credential Enrollment Manager Service Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1235P3HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-09-11
CVE-2019-1235 [HIGH] CWE-346 CVE-2019-1235: An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server process does not validate the source of input or commands it receives, aka 'Windows Text Service Framework Elevation of Privilege Vulnerability'.
nvd
CVE-2025-59033P3HIGHCVSS 7.4≥ 10, ≤ Server 20252025-09-08
CVE-2025-59033 [HIGH] CWE-420 CVE-2025-59033: The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (W The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code signer certificate are properly blocked, but entries that specify the signing certificate's TBS hash along with a 'FileAttribRef' qualifier (such as file name or version) may
nvd
CVE-2020-1217P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+7 more2020-06-09
CVE-2020-1217 [HIGH] CVE-2020-1217: An information disclosure vulnerability exists when the Windows Runtime improperly handles objects i An information disclosure vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Information Disclosure Vulnerability'.
nvd
CVE-2020-0660P3HIGHCVSS 7.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+14 more2020-02-11
CVE-2020-0660 [HIGH] CVE-2020-0660: A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
nvd
CVE-2020-1231P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+14 more2020-06-09
CVE-2020-1231 [HIGH] CVE-2020-1231: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects i An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE-2020-1282, CVE-2020-1304, CVE-2020-1306, CVE-2020-1334.
nvd
CVE-2020-1287P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1709 for x64-based Systems+11 more2020-06-09
CVE-2020-1287 [HIGH] CVE-2020-1287: An elevation of privilege vulnerability exists in the way that the Windows WalletService handles obj An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletService Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1294.
nvd
CVE-2020-1291P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-06-09
CVE-2020-1291 [HIGH] CVE-2020-1291: An elevation of privilege vulnerability exists in the way that the Windows Network Connections Servi An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1280P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+7 more2020-06-09
CVE-2020-1280 [HIGH] CVE-2020-1280: An elevation of privilege vulnerability exists in the way that the Windows Bluetooth Service handles An elevation of privilege vulnerability exists in the way that the Windows Bluetooth Service handles objects in memory, aka 'Windows Bluetooth Service Elevation of Privilege Vulnerability'.
nvd
CVE-2019-0838P3HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-04-09
CVE-2019-0838 [HIGH] CVE-2019-0838: An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses cred An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses credentials to Windows Credential Manager, aka 'Windows Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0839.
nvd
CVE-2019-1393P3HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+5 more2019-11-12
CVE-2019-1393 [HIGH] CWE-787 CVE-2019-1393: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1394, CVE-2019-1395, CVE-2019-1396, CVE-2019-1408, CVE-2019-1434.
nvd
CVE-2020-0791P3HIGHCVSS 7.8v10 Version 1607 for 32-bit Systemsv10 Version 1607 for x64-based Systems2020-03-12
CVE-2020-0791 [HIGH] CVE-2020-0791: An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handle An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0898.
nvd
CVE-2019-0892P3HIGHCVSS 7.8v10 Version 1709 for 32-bit Systemsv10 Version 1709 for x64-based Systems+7 more2019-05-16
CVE-2019-0892 [HIGH] CVE-2019-0892: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1341P3HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-10-10
CVE-2019-1341 [HIGH] CVE-2019-1341: An elevation of privilege vulnerability exists when umpo.dll of the Power Service, improperly handle An elevation of privilege vulnerability exists when umpo.dll of the Power Service, improperly handles a Registry Restore Key function, aka 'Windows Power Service Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1256P3HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-09-11
CVE-2019-1256 [HIGH] CVE-2019-1256: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1285.
nvd