Microsoft Windows vulnerabilities
459 known vulnerabilities affecting microsoft/windows.
Total CVEs
459
CISA KEV
22
actively exploited
Public exploits
29
Exploited in wild
30
Severity breakdown
CRITICAL12HIGH301MEDIUM144LOW2
Vulnerabilities
Page 15 of 23
CVE-2020-1279P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+9 more2020-06-09
CVE-2020-1279 [HIGH] CVE-2020-1279: An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly load spotli
An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly load spotlight images from a secure location, aka 'Windows Lockscreen Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1087P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-05-21
CVE-2020-1087 [HIGH] CVE-2020-1087: An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1114.
nvd
CVE-2020-1124P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+9 more2020-05-21
CVE-2020-1124 [HIGH] CVE-2020-1124: An elevation of privilege vulnerability exists when the Windows State Repository Service improperly
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1131, CVE-2020-1134, CVE-2020-1144, CVE-2020-1184, CVE-2020-1185, CVE-2020-1186, CVE-2020-1187, CVE-2020-1188, CVE-2020-1189
nvd
CVE-2022-50238P3HIGHCVSS 7.4≥ 10, ≤ Server 20252025-09-08
CVE-2022-50238 [HIGH] CWE-820 CVE-2022-50238: The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online Micr
The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online Microsoft recommended driver block rules. Some entries present on the online list have been excluded from the on-endpoint blocklist longer than the expected periodic monthly Windows updates. It is possible to fully synchronize the driver blocklist using WDA
nvd
CVE-2019-0758P3MEDIUMCVSS 6.5v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-05-16
CVE-2019-0758 [MEDIUM] CVE-2019-0758: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0882, CVE-2019-0961.
nvd
CVE-2019-0696P3HIGHCVSS 7.8v10 Version 1607 for 32-bit Systemsv10 Version 1607 for x64-based Systems+11 more2019-04-09
CVE-2019-0696 [HIGH] CVE-2019-0696: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0635P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+14 more2020-01-14
CVE-2020-0635 [HIGH] CWE-269 CVE-2020-0635: An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly h
An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0644.
nvd
CVE-2019-1320P3HIGHCVSS 7.8v10 Version 1703 for 32-bit Systemsv10 Version 1703 for x64-based Systems+9 more2019-10-10
CVE-2019-1320 [HIGH] CVE-2019-1320: An elevation of privilege vulnerability exists when Windows improperly handles authentication reques
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1322, CVE-2019-1340.
nvd
CVE-2019-1090P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+4 more2019-07-15
CVE-2019-1090 [HIGH] CVE-2019-1090: An elevation of privilege vulnerability exists in the way that the dnsrslvr.dll handles objects in m
An elevation of privilege vulnerability exists in the way that the dnsrslvr.dll handles objects in memory, aka 'Windows dnsrlvr.dll Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1067P3HIGHCVSS 7.8v10 for 32-bit Systemsv10 for x64-based Systems+13 more2019-07-15
CVE-2019-1067 [HIGH] CVE-2019-1067: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0788P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-03-12
CVE-2020-0788 [HIGH] CVE-2020-0788: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0877, CVE-2020-0887.
nvd
CVE-2020-0777P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+14 more2020-03-12
CVE-2020-0777 [HIGH] CVE-2020-0777: An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handl
An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0797, CVE-2020-0800, CVE-2020-0864, CVE-2020-0865, CVE-2020-0866, CVE-2020-0897.
nvd
CVE-2020-0781P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-03-12
CVE-2020-0781 [HIGH] CVE-2020-0781: An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) servi
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0783.
nvd
CVE-2020-0940P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+9 more2020-04-15
CVE-2020-0940 [HIGH] CVE-2020-0940: An elevation of privilege vulnerability exists in the way the Windows Push Notification Service hand
An elevation of privilege vulnerability exists in the way the Windows Push Notification Service handles objects in memory, aka 'Windows Push Notification Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1001, CVE-2020-1006, CVE-2020-1017.
nvd
CVE-2020-1004P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-04-15
CVE-2020-1004 [HIGH] CVE-2020-1004: An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handle
An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0840P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+11 more2020-03-12
CVE-2020-0840 [HIGH] CVE-2020-0840: An elevation of privilege vulnerability exists when Windows improperly handles hard links, aka 'Wind
An elevation of privilege vulnerability exists when Windows improperly handles hard links, aka 'Windows Hard Link Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0841, CVE-2020-0849, CVE-2020-0896.
nvd
CVE-2019-1407P3HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+16 more2019-11-12
CVE-2019-1407 [HIGH] CVE-2019-1407: An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handle
An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1433, CVE-2019-1435, CVE-2019-1437, CVE-2019-1438.
nvd
CVE-2019-1086P3HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-07-15
CVE-2019-1086 [HIGH] CVE-2019-1086: An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of P
An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1087, CVE-2019-1088.
nvd
CVE-2020-0679P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-02-11
CVE-2020-0679 [HIGH] CVE-2020-0679: An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Servic
An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Service handles objects in memory, aka 'Windows Function Discovery Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0680, CVE-2020-0682.
nvd
CVE-2020-0666P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-02-11
CVE-2020-0666 [HIGH] CVE-2020-0666: An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles ob
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0667, CVE-2020-0735, CVE-2020-0752.
nvd