cbcvebase.

Microsoft Windows vulnerabilities

459 known vulnerabilities affecting microsoft/windows.

Total CVEs
459
CISA KEV
22
actively exploited
Public exploits
29
Exploited in wild
30
Severity breakdown
CRITICAL12HIGH301MEDIUM144LOW2

Vulnerabilities

Page 3 of 23
CVE-2020-1301P2HIGHCVSS 8.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-06-09
CVE-2020-1301 [HIGH] CVE-2020-1301: A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0 A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0 (SMBv1) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'.
nvd
CVE-2019-0732P3HIGHCVSS 7.8PoCv7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-04-09
CVE-2019-0732 [HIGH] CWE-863 CVE-2019-0732: A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass De A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Security Feature Bypass Vulnerability'.
nvd
CVE-2019-1476P3HIGHCVSS 7.8PoCv10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+7 more2019-12-10
CVE-2019-1476 [HIGH] CVE-2019-1476: An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improp An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1483.
nvd
CVE-2019-0730P3HIGHCVSS 7.8PoCv10 Version 1703 for 32-bit Systemsv10 Version 1703 for x64-based Systems+9 more2019-04-09
CVE-2019-0730 [HIGH] CWE-264 CVE-2019-0730: An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV dr An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836, CVE-2019-0841.
nvd
CVE-2019-0735P3HIGHCVSS 7.8PoCv7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-04-09
CVE-2019-0735 [HIGH] CWE-269 CVE-2019-0735: An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CS An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory, aka 'Windows CSRSS Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1244P3MEDIUMCVSS 6.5PoCv10 Version 1703 for 32-bit Systemsv10 Version 1703 for x64-based Systems+9 more2019-09-11
CVE-2019-1244 [MEDIUM] CWE-200 CVE-2019-1244: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1245, CVE-2019-1251.
nvd
CVE-2019-0881P3HIGHCVSS 7.8PoCv7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-05-16
CVE-2019-0881 [HIGH] CWE-522 CVE-2019-0881: An elevation of privilege vulnerability exists when the Windows Kernel improperly handles key enumer An elevation of privilege vulnerability exists when the Windows Kernel improperly handles key enumeration, aka 'Windows Kernel Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0729P2HIGHCVSS 8.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-02-11
CVE-2020-0729 [HIGH] CVE-2020-0729: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
nvd
CVE-2019-1343P3MEDIUMCVSS 6.5PoCv8.1 for 32-bit systemsv8.1 for x64-based systems+16 more2019-10-10
CVE-2019-1343 [MEDIUM] CVE-2019-1343: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1346, CVE-2019-1347.
nvd
CVE-2019-1358P3HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-10-10
CVE-2019-1358 [HIGH] CVE-2019-1358: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1359.
nvd
CVE-2019-0853P2HIGHCVSS 8.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-04-09
CVE-2019-0853 [HIGH] CWE-824 CVE-2019-0853: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2019-0603P3HIGHCVSS 7.5v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+11 more2019-04-08
CVE-2019-0603 [HIGH] CVE-2019-0603: A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system. To exploit the vulnerability, an attacker could create a specially crafted request, causing Windows to
nvd
CVE-2020-1436P2HIGHCVSS 8.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-07-14
CVE-2020-1436 [HIGH] CWE-787 CVE-2020-1436: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Windows Font Library Remote Code Execution Vulnerability'.
nvd
CVE-2008-3012P2CRITICALCVSS 9.3v2003_server2008-09-11
CVE-2008-3012 [CRITICAL] CWE-119 CVE-2008-3012: gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 an gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 20
nvd
CVE-2019-1468P3HIGHCVSS 8.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2019-12-10
CVE-2019-1468 [HIGH] CWE-787 CVE-2019-1468: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code Execution Vulnerability'.
nvd
CVE-2019-1333P2HIGHCVSS 8.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-10-10
CVE-2019-1333 [HIGH] CVE-2019-1333: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.
nvd
CVE-2020-0687P2HIGHCVSS 8.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-04-15
CVE-2020-0687 [HIGH] CVE-2020-0687: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'.
nvd
CVE-2020-0964P2HIGHCVSS 8.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-04-15
CVE-2020-0964 [HIGH] CVE-2020-0964: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2008-5112P3MEDIUMCVSS 5.0PoCvserver_20032008-11-17
CVE-2008-5112 [MEDIUM] CWE-200 CVE-2008-5112: The LDAP server in Active Directory in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 respon The LDAP server in Active Directory in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 responds differently to a failed bind attempt depending on whether the user account exists and is permitted to login, which allows remote attackers to enumerate valid usernames via a series of LDAP bind requests, as demonstrated by ldapuserenum.
nvd
CVE-2020-0881P3HIGHCVSS 8.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-03-12
CVE-2020-0881 [HIGH] CVE-2020-0881: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0883.
nvd
Microsoft Windows vulnerabilities | cvebase