cbcvebase.

Microsoft Windows 7 vulnerabilities

881 known vulnerabilities affecting microsoft/windows_7.

Total CVEs
881
CISA KEV
35
actively exploited
Public exploits
45
Exploited in wild
50
Severity breakdown
CRITICAL25HIGH656MEDIUM198LOW2

Vulnerabilities

Page 16 of 45
CVE-2019-0906P3HIGHCVSS 7.8≥ 6.1.0, < publication2019-06-12
CVE-2019-0906 [HIGH] CWE-129 CVE-2019-0906: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vul
nvd
CVE-2020-16863P3HIGHCVSS 7.5≥ 6.1.0, < publication2020-10-16
CVE-2020-16863 [HIGH] CVE-2020-16863: <p>A denial of service vulnerability exists in Windows Remote Desktop Service when an attacker conne A denial of service vulnerability exists in Windows Remote Desktop Service when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the Remote Desktop Service on the target system to stop responding. To exploit this vulnerability, an attacker would need
nvd
CVE-2019-1009P3MEDIUMCVSS 4.7≥ 6.1.0, < publication2019-06-12
CVE-2019-1009 [MEDIUM] CWE-200 CVE-2019-1009: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2020-1562P3HIGHCVSS 7.8≥ 6.1.0, < publication2020-08-17
CVE-2020-1562 [HIGH] CVE-2020-1562: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have to open a specially crafted file. The security update addresses the vulnerability by correct
nvd
CVE-2021-1668P3HIGHCVSS 7.8≥ 6.1.0, < publication2021-01-12
CVE-2021-1668 [HIGH] CVE-2021-1668: Microsoft DTV-DVD Video Decoder Remote Code Execution Vulnerability Microsoft DTV-DVD Video Decoder Remote Code Execution Vulnerability
nvd
CVE-2021-26415P3HIGHCVSS 7.8≥ 6.1.0, < publication2021-04-13
CVE-2021-26415 [HIGH] CWE-20 CVE-2021-26415: Windows Installer Elevation of Privilege Vulnerability Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2019-0985P3HIGHCVSS 7.8≥ 6.1.0, < publication2019-06-12
CVE-2019-0985 [HIGH] CWE-787 CVE-2019-0985: A remote code execution vulnerability exists when the Microsoft Speech API (SAPI) improperly handles A remote code execution vulnerability exists when the Microsoft Speech API (SAPI) improperly handles text-to-speech (TTS) input. The vulnerability could corrupt memory in a way that enables an attacker to execute arbitrary code in the context of the current user. To exploit the vulnerability, an attacker would need to convince a user to open a specially
nvd
CVE-2022-29115P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.259542022-05-10
CVE-2022-29115 [HIGH] CVE-2022-29115: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2021-27089P3HIGHCVSS 7.8≥ 6.1.0, < publication2021-04-13
CVE-2021-27089 [HIGH] CVE-2021-27089: Microsoft Internet Messaging API Remote Code Execution Vulnerability Microsoft Internet Messaging API Remote Code Execution Vulnerability
nvd
CVE-2022-21913P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.258292022-01-11
CVE-2022-21913 [HIGH] CVE-2022-21913: Local Security Authority (Domain Policy) Remote Protocol Security Feature Bypass Local Security Authority (Domain Policy) Remote Protocol Security Feature Bypass
nvd
CVE-2022-22027P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.260222022-07-12
CVE-2022-22027 [HIGH] CVE-2022-22027: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2022-22024P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.260222022-07-12
CVE-2022-22024 [HIGH] CVE-2022-22024: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2020-0790P3HIGHCVSS 7.8≥ 6.1.0, < publication2020-09-11
CVE-2020-0790 [HIGH] CVE-2020-0790: <p>A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity. This vulnerability by itself does not allow arbitrary code execution; however, it could allow arbitrary code to be run if th
nvd
CVE-2019-1028P3HIGHCVSS 7.8≥ 6.1.0, < publication2019-06-12
CVE-2019-1028 [HIGH] CVE-2019-1028: An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited th An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that could exploit the vulnerability. This vulnerability by itself does not allow arbitrary code to be run. Howe
nvd
CVE-2022-41118P3HIGHCVSS 7.5vsp1≥ 6.1.0, < 6.1.7601.262212022-11-09
CVE-2022-41118 [HIGH] CWE-362 CVE-2022-41118: Windows Scripting Languages Remote Code Execution Vulnerability Windows Scripting Languages Remote Code Execution Vulnerability
nvd
CVE-2021-26435P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.257122021-09-15
CVE-2021-26435 [HIGH] CWE-787 CVE-2021-26435: Windows Scripting Engine Memory Corruption Vulnerability Windows Scripting Engine Memory Corruption Vulnerability
nvd
CVE-2019-0908P3HIGHCVSS 7.8≥ 6.1.0, < publication2019-06-12
CVE-2019-0908 [HIGH] CVE-2019-0908: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerabili
nvd
CVE-2019-1157P3HIGHCVSS 7.8≥ 6.1.0, < publication2019-08-14
CVE-2019-1157 [HIGH] CWE-94 CVE-2019-1157: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vuln
nvd
CVE-2019-1146P3HIGHCVSS 7.8≥ 6.1.0, < publication2019-08-14
CVE-2019-1146 [HIGH] CVE-2019-1146: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerabili
nvd
CVE-2019-1156P3HIGHCVSS 7.8≥ 6.1.0, < publication2019-08-14
CVE-2019-1156 [HIGH] CVE-2019-1156: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerabili
nvd
Microsoft Windows 7 vulnerabilities | cvebase