cbcvebase.

Microsoft Windows vulnerabilities

459 known vulnerabilities affecting microsoft/windows.

Total CVEs
459
CISA KEV
22
actively exploited
Public exploits
29
Exploited in wild
30
Severity breakdown
CRITICAL12HIGH301MEDIUM144LOW2

Vulnerabilities

Page 9 of 23
CVE-2020-1396P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-07-14
CVE-2020-1396 [HIGH] CVE-2020-1396: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Loc An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system, aka 'Windows ALPC Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0844P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-03-12
CVE-2020-0844 [HIGH] CVE-2020-0844: An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'.
nvd
CVE-2022-40732P3HIGHCVSS 7.5vBuild 22000.5932024-12-18
CVE-2022-40732 [HIGH] CWE-476 CVE-2022-40732: An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys drive An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-crafted set of syscalls can lead to a reboot. An unprivileged user can run specially-crafted code t
nvd
CVE-2019-1326P3HIGHCVSS 7.5v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-10-10
CVE-2019-1326 [HIGH] CVE-2019-1326: A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
nvd
CVE-2020-1028P3HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 12020-05-21
CVE-2020-1028 [HIGH] CWE-787 CVE-2020-1028: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1126, CVE-2020-1136, CVE-2020-1150.
nvd
CVE-2020-1211P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+9 more2020-06-09
CVE-2020-1211 [HIGH] CVE-2020-1211: An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Servic An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1314P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-06-09
CVE-2020-1314 [HIGH] CVE-2020-1314: An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server fails to properly handle messages sent from TSF clients, aka 'Windows Text Service Framework Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1362P3HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 12019-10-10
CVE-2019-1362 [HIGH] CVE-2019-1362: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1364.
nvd
CVE-2019-0627P3HIGHCVSS 7.8v10 for 32-bit Systemsv10 for x64-based Systems+13 more2019-03-05
CVE-2019-0627 [HIGH] CVE-2019-0627: A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass De A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0631, CVE-2019-0632.
nvd
CVE-2020-1424P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+4 more2020-07-14
CVE-2020-1424 [HIGH] CVE-2020-1424: An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handl An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0634P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-01-14
CVE-2020-0634 [HIGH] CWE-416 CVE-2020-0634: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1267P3HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+17 more2019-09-11
CVE-2019-1267 [HIGH] CWE-59 CVE-2019-1267: An elevation of privilege vulnerability exists in Microsoft Compatibility Appraiser where a configur An elevation of privilege vulnerability exists in Microsoft Compatibility Appraiser where a configuration file, with local privileges, is vulnerable to symbolic link and hard link attacks, aka 'Microsoft Compatibility Appraiser Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1207P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+14 more2020-06-09
CVE-2020-1207 [HIGH] CWE-416 CVE-2020-1207: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1247, CVE-2020-1251, CVE-2020-1253, CVE-2020-1310.
nvd
CVE-2020-0861P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+14 more2020-03-12
CVE-2020-0861 [HIGH] CVE-2020-0861: An information disclosure vulnerability exists when the Windows Network Driver Interface Specificati An information disclosure vulnerability exists when the Windows Network Driver Interface Specification (NDIS) improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Network Driver Interface Specification (NDIS) Information Disclosure Vulnerability'.
nvd
CVE-2019-1268P3HIGHCVSS 7.8v7 for 32-bit Systems Service Pack 1v7 for x64-based Systems Service Pack 1+18 more2019-09-11
CVE-2019-1268 [HIGH] CVE-2019-1268: An elevation of privilege exists when Winlogon does not properly handle file path information, aka ' An elevation of privilege exists when Winlogon does not properly handle file path information, aka 'Winlogon Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1477P3HIGHCVSS 7.8v10 Version 1809 for 32-bit Systemsv10 Version 1809 for x64-based Systems+1 more2019-12-10
CVE-2019-1477 [HIGH] CVE-2019-1477: An elevation of privilege vulnerability exists when the Windows Printer Service improperly validates An elevation of privilege vulnerability exists when the Windows Printer Service improperly validates file paths while loading printer drivers, aka 'Windows Printer Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0776P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+14 more2020-03-12
CVE-2020-0776 [HIGH] CVE-2020-0776: An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly ha An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0858.
nvd
CVE-2020-0769P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+16 more2020-03-12
CVE-2020-0769 [HIGH] CVE-2020-0769: An elevation of privilege vulnerability exists when the Windows CSC Service improperly handles memor An elevation of privilege vulnerability exists when the Windows CSC Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows CSC Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0771.
nvd
CVE-2020-1336P3HIGHCVSS 7.8v10 Version 1803 for 32-bit Systemsv10 Version 1803 for x64-based Systems+11 more2020-07-14
CVE-2020-1336 [HIGH] CVE-2020-1336: An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addresses the vulnerabili
nvd
CVE-2020-0757P3HIGHCVSS 7.8v10 Version 1809 for ARM64-based Systemsv10 Version 1809 for 32-bit Systems+1 more2020-02-11
CVE-2020-0757 [HIGH] CVE-2020-0757: An elevation of privilege vulnerability exists when Windows improperly handles Secure Socket Shell r An elevation of privilege vulnerability exists when Windows improperly handles Secure Socket Shell remote commands, aka 'Windows SSH Elevation of Privilege Vulnerability'.
nvd
Microsoft Windows vulnerabilities | cvebase