Microsoft Windows vulnerabilities
424 known vulnerabilities affecting microsoft/windows.
Total CVEs
424
CISA KEV
21
actively exploited
Public exploits
27
Exploited in wild
28
Severity breakdown
CRITICAL11HIGH275MEDIUM136LOW2
Vulnerabilities
Page 8 of 22
CVE-2019-1362P3HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 12019-10-10
CVE-2019-1362 [HIGH] CVE-2019-1362: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1364.
nvd
CVE-2019-0766P3HIGHCVSS 7.8v10 Version 1607 for 32-bit Systemsv10 Version 1607 for x64-based Systems+11 more2019-04-09
CVE-2019-0766 [HIGH] CVE-2019-0766: An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file cr
An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0704P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+11 more2020-02-11
CVE-2020-0704 [HIGH] CVE-2020-0704: An elevation of privilege vulnerability exists when the Windows Wireless Network Manager improperly
An elevation of privilege vulnerability exists when the Windows Wireless Network Manager improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Wireless Network Manager Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1269P3HIGHCVSS 7.8v10 for 32-bit Systemsv10 for x64-based Systems+13 more2019-09-11
CVE-2019-1269 [HIGH] CVE-2019-1269: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Loc
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system, aka 'Windows ALPC Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1272.
nvd
CVE-2020-0641P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+14 more2020-01-14
CVE-2020-0641 [HIGH] CVE-2020-0641: An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in
An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1254P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-06-09
CVE-2020-1254 [HIGH] CVE-2020-1254: An elevation of privilege vulnerability exists when Windows Modules Installer Service improperly han
An elevation of privilege vulnerability exists when Windows Modules Installer Service improperly handles class object members.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows Modules Installer Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0727P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+11 more2020-02-11
CVE-2020-0727 [HIGH] CVE-2020-0727: An elevation of privilege vulnerability exists when the Connected User Experiences and Telemetry Ser
An elevation of privilege vulnerability exists when the Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1232P3HIGHCVSS 7.8v10 for 32-bit Systemsv10 for x64-based Systems+13 more2019-09-11
CVE-2019-1232 [HIGH] CVE-2019-1232: An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service i
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operations, aka 'Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1271P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+13 more2020-06-09
CVE-2020-1271 [HIGH] CVE-2020-1271: An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles fi
An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0844P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-03-12
CVE-2020-0844 [HIGH] CVE-2020-0844: An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service
An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1431P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+4 more2020-07-14
CVE-2020-1431 [HIGH] CWE-269 CVE-2020-1431: An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperl
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correc
nvd
CVE-2022-40732P3HIGHCVSS 7.5vBuild 22000.5932024-12-18
CVE-2022-40732 [HIGH] CWE-476 CVE-2022-40732: An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys drive
An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-crafted set of syscalls can lead to a reboot. An unprivileged user can run specially-crafted code t
nvd
CVE-2020-0660P3HIGHCVSS 7.5v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+14 more2020-02-11
CVE-2020-0660 [HIGH] CVE-2020-0660: A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
nvd
CVE-2020-1291P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-06-09
CVE-2020-1291 [HIGH] CVE-2020-1291: An elevation of privilege vulnerability exists in the way that the Windows Network Connections Servi
An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1314P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-06-09
CVE-2020-1314 [HIGH] CVE-2020-1314: An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF
An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server fails to properly handle messages sent from TSF clients, aka 'Windows Text Service Framework Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1280P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+7 more2020-06-09
CVE-2020-1280 [HIGH] CVE-2020-1280: An elevation of privilege vulnerability exists in the way that the Windows Bluetooth Service handles
An elevation of privilege vulnerability exists in the way that the Windows Bluetooth Service handles objects in memory, aka 'Windows Bluetooth Service Elevation of Privilege Vulnerability'.
nvd
CVE-2019-0627P3HIGHCVSS 7.8v10 for 32-bit Systemsv10 for x64-based Systems+13 more2019-03-05
CVE-2019-0627 [HIGH] CVE-2019-0627: A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass De
A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0631, CVE-2019-0632.
nvd
CVE-2020-1424P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+4 more2020-07-14
CVE-2020-1424 [HIGH] CVE-2020-1424: An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handl
An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0634P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-01-14
CVE-2020-0634 [HIGH] CWE-416 CVE-2020-0634: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1207P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+14 more2020-06-09
CVE-2020-1207 [HIGH] CWE-416 CVE-2020-1207: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1247, CVE-2020-1251, CVE-2020-1253, CVE-2020-1310.
nvd