Microsoft Windows vulnerabilities
424 known vulnerabilities affecting microsoft/windows.
Total CVEs
424
CISA KEV
21
actively exploited
Public exploits
27
Exploited in wild
28
Severity breakdown
CRITICAL11HIGH275MEDIUM136LOW2
Vulnerabilities
Page 4 of 22
CVE-2019-0845P3HIGHCVSS 8.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-04-09
CVE-2019-0845 [HIGH] CVE-2019-0845: A remote code execution vulnerability exists when the IOleCvt interface renders ASP webpage content,
A remote code execution vulnerability exists when the IOleCvt interface renders ASP webpage content, aka 'Windows IOleCvt Interface Remote Code Execution Vulnerability'.
nvd
CVE-2020-1281P3HIGHCVSS 8.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-06-09
CVE-2020-1281 [HIGH] CWE-190 CVE-2020-1281: A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate u
A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.
nvd
CVE-2019-1060P3HIGHCVSS 8.8v8.1 for 32-bit systemsv8.1 for x64-based systems+16 more2019-10-10
CVE-2019-1060 [HIGH] CWE-611 CVE-2019-1060: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.
nvd
CVE-2020-0662P3HIGHCVSS 8.8v10 Version 1803 for x64-based Systemsv10 Version 1809 for x64-based Systems+5 more2020-02-11
CVE-2020-0662 [HIGH] CVE-2020-0662: A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka
A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.
nvd
CVE-2019-1365P3CRITICALCVSS 9.9v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+11 more2019-10-10
CVE-2019-1365 [CRITICAL] CVE-2019-1365: An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length o
An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the context of NT AUTHORITY\system escaping the Sandbox.The security update addresses the
nvd
CVE-2019-0842P3HIGHCVSS 8.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-04-09
CVE-2019-0842 [HIGH] CWE-787 CVE-2019-0842: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'.
nvd
CVE-2019-0790P3HIGHCVSS 8.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-04-09
CVE-2019-0790 [HIGH] CWE-611 CVE-2019-0790: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0791, CVE-2019-0792, CVE-2019-0793, CVE-2019-0795.
nvd
CVE-2020-1299P3HIGHCVSS 8.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-06-09
CVE-2020-1299 [HIGH] CVE-2020-1299: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
nvd
CVE-2019-0765P3HIGHCVSS 8.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+16 more2019-04-09
CVE-2019-0765 [HIGH] CWE-787 CVE-2019-0765: A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory,
A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory, aka 'Comctl32 Remote Code Execution Vulnerability'.
nvd
CVE-2020-1435P3HIGHCVSS 8.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-07-14
CVE-2020-1435 [HIGH] CVE-2020-1435: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2019-1441P3HIGHCVSS 8.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 12019-11-12
CVE-2019-1441 [HIGH] CWE-119 CVE-2019-1441: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code Execution Vulnerability'.
nvd
CVE-2019-0756P3HIGHCVSS 8.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+13 more2019-04-09
CVE-2019-0756 [HIGH] CWE-611 CVE-2019-0756: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.
nvd
CVE-2019-0787P3HIGHCVSS 8.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-09-11
CVE-2019-0787 [HIGH] CVE-2019-0787: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0788, CVE-2019-1290, CVE-2019-1291.
nvd
CVE-2019-1439P3MEDIUMCVSS 6.5v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+16 more2019-11-12
CVE-2019-1439 [MEDIUM] CWE-200 CVE-2019-1439: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
nvd
CVE-2019-0786P3CRITICALCVSS 9.8v10 Version 1709 for 32-bit Systemsv10 Version 1709 for x64-based Systems+7 more2019-04-09
CVE-2019-0786 [CRITICAL] CWE-20 CVE-2019-0786: An elevation of privilege vulnerability exists in the Microsoft Server Message Block (SMB) Server wh
An elevation of privilege vulnerability exists in the Microsoft Server Message Block (SMB) Server when an attacker with valid credentials attempts to open a specially crafted file over the SMB protocol on the same machine, aka 'SMB Server Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1166P3MEDIUMCVSS 5.9v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-10-10
CVE-2019-1166 [MEDIUM] CWE-354 CVE-2019-1166: A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to s
A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection, aka 'Windows NTLM Tampering Vulnerability'.
nvd
CVE-2019-0719P3CRITICALCVSS 9.1v10 Version 1709 for x64-based Systemsv10 Version 1803 for x64-based Systems+1 more2019-11-12
CVE-2019-0719 [CRITICAL] CWE-20 CVE-2019-0719: A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fa
A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0721.
nvd
CVE-2020-1286P3HIGHCVSS 8.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+7 more2020-06-09
CVE-2020-1286 [HIGH] CWE-20 CVE-2020-1286: A remote code execution vulnerability exists when the Windows Shell does not properly validate file
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the current user, aka 'Windows Shell Remote Code Execution Vulnerability'.
nvd
CVE-2019-1419P3HIGHCVSS 8.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+16 more2019-11-12
CVE-2019-1419 [HIGH] CVE-2019-1419: A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manage
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts, aka 'OpenType Font Parsing Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1456.
nvd
CVE-2019-1102P3HIGHCVSS 8.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+17 more2019-07-15
CVE-2019-1102 [HIGH] CVE-2019-1102: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd