cbcvebase.

Microsoft Windows vulnerabilities

459 known vulnerabilities affecting microsoft/windows.

Total CVEs
459
CISA KEV
22
actively exploited
Public exploits
29
Exploited in wild
30
Severity breakdown
CRITICAL12HIGH301MEDIUM144LOW2

Vulnerabilities

Page 2 of 23
CVE-2019-1214P2HIGHCVSS 7.8KEVv7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-09-11
CVE-2019-1214 [HIGH] CWE-119 CVE-2019-1214: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.
nvd
CVE-2019-0703P2MEDIUMCVSS 6.5KEVv7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+12 more2019-04-09
CVE-2019-0703 [MEDIUM] CVE-2019-0703: An information disclosure vulnerability exists in the way that the Windows SMB Server handles certai An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0704, CVE-2019-0821.
nvd
CVE-2020-0624P1HIGHCVSS 7.8ExploitedPoCRansomwarev10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-01-14
CVE-2020-0624 [HIGH] CVE-2020-0624: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0642.
nvd
CVE-2020-1048P2HIGHCVSS 7.8ExploitedPoCv10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-05-21
CVE-2020-1048 [HIGH] CWE-669 CVE-2020-1048: An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly all An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Print Spooler Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1070.
nvd
CVE-2019-0623P2HIGHCVSS 7.8ExploitedPoCv7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+15 more2019-03-05
CVE-2019-0623 [HIGH] CVE-2019-0623: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
nvd
CVE-2019-0630P1HIGHCVSS 8.8Exploitedv8.1 for 32-bit systemsv8.1 for x64-based systems+16 more2019-03-05
CVE-2019-0630 [HIGH] CWE-19 CVE-2019-0630: A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0633.
nvd
CVE-2020-0611P1HIGHCVSS 7.5ExploitedRansomwarev10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-01-14
CVE-2020-0611 [HIGH] CVE-2020-0611: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.
nvd
CVE-2019-1108P1MEDIUMCVSS 6.5ExploitedRansomwarev7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-07-15
CVE-2019-1108 [MEDIUM] CWE-200 CVE-2019-1108: An information disclosure vulnerability exists when the Windows RDP client improperly discloses the An information disclosure vulnerability exists when the Windows RDP client improperly discloses the contents of its memory, aka 'Remote Desktop Protocol Client Information Disclosure Vulnerability'.
nvd
CVE-2020-1375P2HIGHCVSS 7.8Exploitedv10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+7 more2020-07-14
CVE-2020-1375 [HIGH] CVE-2020-1375: An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Server Elevation of Privilege Vulnerability'.
nvd
CVE-2019-0784P2HIGHCVSS 7.5Exploitedv7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+14 more2019-04-09
CVE-2019-0784 [HIGH] CWE-787 CVE-2019-0784: A remote code execution vulnerability exists in the way that the ActiveX Data objects (ADO) handles A remote code execution vulnerability exists in the way that the ActiveX Data objects (ADO) handles objects in memory, aka 'Windows ActiveX Remote Code Execution Vulnerability'.
nvd
CVE-2008-4037P2CRITICALCVSS 9.3PoCvserver_2003vxp2008-11-12
CVE-2008-4037 [CRITICAL] CVE-2008-4037: Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold an Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrated by backrush, aka "SMB Credential Reflection Vulnerability." NOTE: some reliable sources report t
nvd
CVE-2007-5348P2CRITICALCVSS 9.3PoCv2003_server2008-09-11
CVE-2007-5348 [CRITICAL] CWE-189 CVE-2007-5348: Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 S Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Serv
nvd
CVE-2019-1117P2HIGHCVSS 8.8PoCv10 Version 1709 for 32-bit Systemsv10 Version 1709 for x64-based Systems+7 more2019-07-15
CVE-2019-1117 [HIGH] CVE-2019-1117: A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123, CVE-2019-1124, CVE-2019-1127, CVE-2019-1128.
nvd
CVE-2019-0626P2CRITICALCVSS 9.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-03-05
CVE-2019-0626 [CRITICAL] CWE-787 CVE-2019-0626: A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends s A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
nvd
CVE-2020-0668P3HIGHCVSS 7.8PoCv10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+7 more2020-02-11
CVE-2020-0668 [HIGH] CWE-732 CVE-2020-0668: An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0669, CVE-2020-0670, CVE-2020-0671, CVE-2020-0672.
nvd
CVE-2020-1421P2HIGHCVSS 8.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+15 more2020-07-14
CVE-2020-1421 [HIGH] CWE-843 CVE-2020-1421: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
nvd
CVE-2019-0618P2HIGHCVSS 8.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-03-05
CVE-2019-0618 [HIGH] CVE-2019-0618: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0662.
nvd
CVE-2020-1300P2HIGHCVSS 8.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-06-09
CVE-2020-1300 [HIGH] CVE-2020-1300: A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files.To exploit the vulnerability, an attacker would have to convince a user to either open a specially crafted cabinet file or spoof a network printer and trick a user into installing a malicious cabinet file disguised as a printer driver.The update addresses
nvd
CVE-2020-0655P2HIGHCVSS 8.0v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-02-11
CVE-2020-0655 [HIGH] CVE-2020-0655: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Termin A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
nvd
CVE-2019-0697P2CRITICALCVSS 9.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+4 more2019-04-09
CVE-2019-0697 [CRITICAL] CWE-787 CVE-2019-0697: A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0698, CVE-2019-0726.
nvd
Microsoft Windows vulnerabilities | cvebase