Microsoft Windows vulnerabilities
459 known vulnerabilities affecting microsoft/windows.
Total CVEs
459
CISA KEV
22
actively exploited
Public exploits
29
Exploited in wild
30
Severity breakdown
CRITICAL12HIGH301MEDIUM144LOW2
Vulnerabilities
Page 5 of 23
CVE-2019-1102P3HIGHCVSS 8.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+17 more2019-07-15
CVE-2019-1102 [HIGH] CVE-2019-1102: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2020-1412P3HIGHCVSS 8.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-07-14
CVE-2020-1412 [HIGH] CWE-269 CVE-2020-1412: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
nvd
CVE-2019-1166P3MEDIUMCVSS 5.9v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-10-10
CVE-2019-1166 [MEDIUM] CWE-354 CVE-2019-1166: A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to s
A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection, aka 'Windows NTLM Tampering Vulnerability'.
nvd
CVE-2019-1419P3HIGHCVSS 8.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+16 more2019-11-12
CVE-2019-1419 [HIGH] CVE-2019-1419: A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manage
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts, aka 'OpenType Font Parsing Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1456.
nvd
CVE-2019-1311P3HIGHCVSS 7.8v8.1 for 32-bit systemsv8.1 for x64-based systems+16 more2019-10-10
CVE-2019-1311 [HIGH] CVE-2019-1311: A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects
A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects in memory, aka 'Windows Imaging API Remote Code Execution Vulnerability'.
nvd
CVE-2020-1117P3HIGHCVSS 8.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+9 more2020-05-21
CVE-2020-1117 [HIGH] CVE-2020-1117: A remote code execution vulnerability exists in the way that the Color Management Module (ICM32.dll)
A remote code execution vulnerability exists in the way that the Color Management Module (ICM32.dll) handles objects in memory, aka 'Microsoft Color Management Remote Code Execution Vulnerability'.
nvd
CVE-2020-1061P3HIGHCVSS 8.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-05-21
CVE-2020-1061 [HIGH] CWE-787 CVE-2020-1061: A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles ob
A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles objects in memory, aka 'Microsoft Script Runtime Remote Code Execution Vulnerability'.
nvd
CVE-2020-0684P3HIGHCVSS 8.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+15 more2020-03-12
CVE-2020-0684 [HIGH] CVE-2020-0684: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
nvd
CVE-2019-0856P3HIGHCVSS 7.2v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-04-09
CVE-2019-0856 [HIGH] CVE-2019-0856: A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka
A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.
nvd
CVE-2019-1252P3MEDIUMCVSS 6.5v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-09-11
CVE-2019-1252 [MEDIUM] CWE-200 CVE-2019-1252: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1286.
nvd
CVE-2020-1112P3CRITICALCVSS 9.9v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-05-21
CVE-2020-1112 [CRITICAL] CWE-434 CVE-2020-1112: An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Serv
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0690P3CRITICALCVSS 9.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+11 more2020-03-12
CVE-2020-0690 [CRITICAL] CVE-2020-0690: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, ak
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1374P3HIGHCVSS 7.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-07-14
CVE-2020-1374 [HIGH] CVE-2020-1374: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.
nvd
CVE-2019-0889P3HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-05-16
CVE-2019-0889 [HIGH] CVE-2019-0889: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0890, CVE-2019-0891, CVE-2019-0893, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0899, CVE-2019-0900, CVE
nvd
CVE-2020-1408P3HIGHCVSS 8.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-07-14
CVE-2020-1408 [HIGH] CWE-346 CVE-2020-1408: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'.
nvd
CVE-2019-1280P3HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-09-11
CVE-2019-1280 [HIGH] CWE-59 CVE-2019-1280: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
nvd
CVE-2020-1317P3HIGHCVSS 8.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-06-09
CVE-2020-1317 [HIGH] CVE-2020-1317: An elevation of privilege vulnerability exists when Group Policy improperly checks access, aka 'Grou
An elevation of privilege vulnerability exists when Group Policy improperly checks access, aka 'Group Policy Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1400P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-07-14
CVE-2020-1400 [HIGH] CWE-191 CVE-2020-1400: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1401, CVE-2020-1407.
nvd
CVE-2019-1006P3HIGHCVSS 7.5v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-07-15
CVE-2019-1006 [HIGH] CWE-295 CVE-2019-1006: An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.
nvd
CVE-2020-0910P3HIGHCVSS 8.4v10 Version 1809 for x64-based Systems2020-04-15
CVE-2020-0910 [HIGH] CWE-20 CVE-2020-0910: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'.
nvd