Microsoft Windows vulnerabilities

831 known vulnerabilities affecting microsoft/windows.

Total CVEs
831
CISA KEV
31
actively exploited
Public exploits
51
Exploited in wild
32
Severity breakdown
CRITICAL15HIGH591MEDIUM223LOW2

Vulnerabilities

Page 29 of 42
CVE-2019-1309MEDIUMCVSS 6.8v10 Version 1709 for x64-based Systemsv10 Version 1803 for x64-based Systems+1 more2019-11-12
CVE-2019-1309 [MEDIUM] CVE-2019-1309: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged use A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0712, CVE-2019-1310, CVE-2019-1399.
cvelistv5
CVE-2019-1391MEDIUMCVSS 6.5v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+16 more2019-11-12
CVE-2019-1391 [MEDIUM] CVE-2019-1391: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability' A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2018-12207.
cvelistv5
CVE-2019-1409MEDIUMCVSS 5.5v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+16 more2019-11-12
CVE-2019-1409 [MEDIUM] CWE-665 CVE-2019-1409: An information disclosure vulnerability exists when the Windows Remote Procedure Call (RPC) runtime An information disclosure vulnerability exists when the Windows Remote Procedure Call (RPC) runtime improperly initializes objects in memory, aka 'Windows Remote Procedure Call Information Disclosure Vulnerability'.
cvelistv5nvd
CVE-2019-1418LOWCVSS 3.3v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+16 more2019-11-12
CVE-2019-1418 [LOW] CWE-200 CVE-2019-1418: An information vulnerability exists when Windows Modules Installer Service improperly discloses file An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules Installer Service Information Disclosure Vulnerability'.
cvelistv5nvd
CVE-2019-1365CRITICALCVSS 9.9v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+11 more2019-10-10
CVE-2019-1365 [CRITICAL] CVE-2019-1365: An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length o An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the context of NT AUTHORITY\system escaping the Sandbox.The security update addresses the
cvelistv5nvd
CVE-2019-1320HIGHCVSS 7.8v10 Version 1703 for 32-bit Systemsv10 Version 1703 for x64-based Systems+9 more2019-10-10
CVE-2019-1320 [HIGH] CVE-2019-1320: An elevation of privilege vulnerability exists when Windows improperly handles authentication reques An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1322, CVE-2019-1340.
cvelistv5nvd
CVE-2019-1339HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-10-10
CVE-2019-1339 [HIGH] CVE-2019-1339: An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manage An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1315, CVE-2019-1342.
cvelistv5
CVE-2019-1316HIGHCVSS 7.8v10 for 32-bit Systemsv10 for x64-based Systems+13 more2019-10-10
CVE-2019-1316 [HIGH] CVE-2019-1316: An elevation of privilege vulnerability exists in Microsoft Windows Setup when it does not properly An elevation of privilege vulnerability exists in Microsoft Windows Setup when it does not properly handle privileges, aka 'Microsoft Windows Setup Elevation of Privilege Vulnerability'.
cvelistv5nvd
CVE-2019-1315HIGHCVSS 7.8KEVv7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-10-10
CVE-2019-1315 [HIGH] CWE-59 CVE-2019-1315: An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handl An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1339, CVE-2019-1342.
cvelistv5nvd
CVE-2019-1341HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-10-10
CVE-2019-1341 [HIGH] CVE-2019-1341: An elevation of privilege vulnerability exists when umpo.dll of the Power Service, improperly handle An elevation of privilege vulnerability exists when umpo.dll of the Power Service, improperly handles a Registry Restore Key function, aka 'Windows Power Service Elevation of Privilege Vulnerability'.
cvelistv5nvd
CVE-2019-1311HIGHCVSS 7.8v8.1 for 32-bit systemsv8.1 for x64-based systems+16 more2019-10-10
CVE-2019-1311 [HIGH] CVE-2019-1311: A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects in memory, aka 'Windows Imaging API Remote Code Execution Vulnerability'.
cvelistv5nvd
CVE-2019-1060HIGHCVSS 8.8v8.1 for 32-bit systemsv8.1 for x64-based systems+16 more2019-10-10
CVE-2019-1060 [HIGH] CWE-611 CVE-2019-1060: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.
cvelistv5nvd
CVE-2019-1323HIGHCVSS 7.8v10 Version 1809 for 32-bit Systemsv10 Version 1809 for x64-based Systems+1 more2019-10-10
CVE-2019-1323 [HIGH] CVE-2019-1323: An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does n An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does not properly handle privileges, aka 'Microsoft Windows Update Client Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1336.
cvelistv5nvd
CVE-2019-1333HIGHCVSS 8.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-10-10
CVE-2019-1333 [HIGH] CVE-2019-1333: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.
cvelistv5nvd
CVE-2019-1321HIGHCVSS 7.8v10 Version 1703 for 32-bit Systemsv10 Version 1703 for x64-based Systems+9 more2019-10-10
CVE-2019-1321 [HIGH] CVE-2019-1321: An elevation of privilege vulnerability exists when Windows CloudStore improperly handles file Discr An elevation of privilege vulnerability exists when Windows CloudStore improperly handles file Discretionary Access Control List (DACL), aka 'Microsoft Windows CloudStore Elevation of Privilege Vulnerability'.
cvelistv5nvd
CVE-2019-1326HIGHCVSS 7.5v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-10-10
CVE-2019-1326 [HIGH] CVE-2019-1326: A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
cvelistv5nvd
CVE-2019-1364HIGHCVSS 7.8PoCv7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 12019-10-10
CVE-2019-1364 [HIGH] CVE-2019-1364: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1362.
cvelistv5
CVE-2019-1358HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-10-10
CVE-2019-1358 [HIGH] CVE-2019-1358: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1359.
cvelistv5nvd
CVE-2019-1322HIGHCVSS 7.8KEVPoCv10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+4 more2019-10-10
CVE-2019-1322 [HIGH] CVE-2019-1322: An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1320, CVE-2019-1340.
cvelistv5
CVE-2019-1340HIGHCVSS 7.8v10 Version 1703 for 32-bit Systemsv10 Version 1703 for x64-based Systems+9 more2019-10-10
CVE-2019-1340 [HIGH] CVE-2019-1340: An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary locations An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1320, CVE-2019-1322.
cvelistv5