Microsoft Windows vulnerabilities

831 known vulnerabilities affecting microsoft/windows.

Total CVEs
831
CISA KEV
31
actively exploited
Public exploits
51
Exploited in wild
32
Severity breakdown
CRITICAL15HIGH591MEDIUM223LOW2

Vulnerabilities

Page 26 of 42
CVE-2019-1471HIGHCVSS 8.2v10 Version 1803 for x64-based Systemsv10 Version 1809 for x64-based Systems2019-12-10
CVE-2019-1471 [HIGH] CWE-20 CVE-2019-1471: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'.
cvelistv5nvd
CVE-2019-1478HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 12019-12-10
CVE-2019-1478 [HIGH] CVE-2019-1478: An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Server Elevation of Privilege Vulnerability'.
cvelistv5nvd
CVE-2019-1469MEDIUMCVSS 5.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2019-12-10
CVE-2019-1469 [MEDIUM] CWE-200 CVE-2019-1469: An information disclosure vulnerability exists when the win32k component improperly provides kernel An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.
cvelistv5nvd
CVE-2019-1480MEDIUMCVSS 4.3v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 12019-12-10
CVE-2019-1480 [MEDIUM] CWE-125 CVE-2019-1480: An information disclosure vulnerability exists in Windows Media Player when it fails to properly han An information disclosure vulnerability exists in Windows Media Player when it fails to properly handle objects in memory, aka 'Windows Media Player Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1481.
cvelistv5nvd
CVE-2019-1472MEDIUMCVSS 5.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2019-12-10
CVE-2019-1472 [MEDIUM] CWE-200 CVE-2019-1472: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1474.
cvelistv5nvd
CVE-2019-1470MEDIUMCVSS 6.0v10 Version 1803 for x64-based Systemsv10 Version 1809 for x64-based Systems+5 more2019-12-10
CVE-2019-1470 [MEDIUM] CWE-20 CVE-2019-1470: An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.
cvelistv5nvd
CVE-2019-1465MEDIUMCVSS 6.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2019-12-10
CVE-2019-1465 [MEDIUM] CWE-125 CVE-2019-1465: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1466, CVE-2019-1467.
cvelistv5nvd
CVE-2019-1467MEDIUMCVSS 6.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2019-12-10
CVE-2019-1467 [MEDIUM] CVE-2019-1467: An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Inform An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1465, CVE-2019-1466.
cvelistv5
CVE-2019-1466MEDIUMCVSS 6.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2019-12-10
CVE-2019-1466 [MEDIUM] CVE-2019-1466: An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Inform An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1465, CVE-2019-1467.
cvelistv5
CVE-2019-1481MEDIUMCVSS 4.3v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 12019-12-10
CVE-2019-1481 [MEDIUM] CVE-2019-1481: An information disclosure vulnerability exists in Windows Media Player when it fails to properly handle objects in memory, aka 'Windows Media Player I An information disclosure vulnerability exists in Windows Media Player when it fails to properly handle objects in memory, aka 'Windows Media Player Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1480.
cvelistv5
CVE-2019-1474MEDIUMCVSS 5.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2019-12-10
CVE-2019-1474 [MEDIUM] CVE-2019-1474: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosur An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1472.
cvelistv5
CVE-2019-1488LOWCVSS 3.3v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2019-12-10
CVE-2019-1488 [LOW] CVE-2019-1488: A security feature bypass vulnerability exists when Microsoft Defender improperly handles specific b A security feature bypass vulnerability exists when Microsoft Defender improperly handles specific buffers, aka 'Microsoft Defender Security Feature Bypass Vulnerability'.
cvelistv5nvd
CVE-2018-12207MEDIUMCVSS 6.5v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+16 more2019-11-14
CVE-2018-12207 [MEDIUM] CWE-20 CVE-2018-12207: Improper invalidation for page table updates by a virtual guest operating system for multiple Intel( Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
nvd
CVE-2019-0721CRITICALCVSS 9.1v10 Version 1709 for x64-based Systemsv10 Version 1803 for x64-based Systems+1 more2019-11-12
CVE-2019-0721 [CRITICAL] CVE-2019-0721: A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticat A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0719.
cvelistv5
CVE-2019-1384CRITICALCVSS 9.9v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+16 more2019-11-12
CVE-2019-1384 [CRITICAL] CWE-522 CVE-2019-1384: A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the sessio A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an attacker could send a specially crafted authentication request, aka 'Microsoft Windows Security Feature Bypass Vulnerability'.
cvelistv5nvd
CVE-2019-0719CRITICALCVSS 9.1v10 Version 1709 for x64-based Systemsv10 Version 1803 for x64-based Systems+1 more2019-11-12
CVE-2019-0719 [CRITICAL] CWE-20 CVE-2019-0719: A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fa A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0721.
cvelistv5nvd
CVE-2019-1395HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+16 more2019-11-12
CVE-2019-1395 [HIGH] CVE-2019-1395: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1393, CVE-2019-1394, CVE-2019-1396, CVE-2019-1408, CVE-2019-1434.
cvelistv5
CVE-2019-1435HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+16 more2019-11-12
CVE-2019-1435 [HIGH] CVE-2019-1435: An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Compone An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1407, CVE-2019-1433, CVE-2019-1437, CVE-2019-1438.
cvelistv5
CVE-2019-1393HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+5 more2019-11-12
CVE-2019-1393 [HIGH] CWE-787 CVE-2019-1393: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1394, CVE-2019-1395, CVE-2019-1396, CVE-2019-1408, CVE-2019-1434.
cvelistv5nvd
CVE-2019-1385HIGHCVSS 7.8KEVPoCv10 Version 1709 for 32-bit Systemsv10 Version 1709 for x64-based Systems+7 more2019-11-12
CVE-2019-1385 [HIGH] CWE-59 CVE-2019-1385: An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperl An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correct
cvelistv5nvd