Microsoft Windows 7 vulnerabilities
906 known vulnerabilities affecting microsoft/windows_7.
Total CVEs
906
CISA KEV
36
actively exploited
Public exploits
47
Exploited in wild
53
Severity breakdown
CRITICAL26HIGH674MEDIUM204LOW2
Vulnerabilities
Page 21 of 46
CVE-2020-1245P3HIGHCVSS 7.8≥ 6.1.0, < publication2020-09-11
CVE-2020-1245 [HIGH] CVE-2020-1245: <p>An elevation of privilege vulnerability exists in Windows when the Win32k component fails to prop
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vul
nvd
CVE-2020-1078P3HIGHCVSS 7.8≥ 6.1.0, < publication2020-05-21
CVE-2020-1078 [HIGH] CVE-2020-1078: An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Insta
An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.
To exploit the vulnerability, an attacker would require unprivileged execution on the victim system. After successfully exploiting the vulnerability, an attacker could run arbitrary code with elevated privileges. An att
nvd
CVE-2023-21675P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21675 [HIGH] CWE-843 CVE-2023-21675: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-21748P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21748 [HIGH] CVE-2023-21748: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-21749P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21749 [HIGH] CWE-20 CVE-2023-21749: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-22043P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.260222022-07-12
CVE-2022-22043 [HIGH] CVE-2022-22043: Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-21774P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21774 [HIGH] CWE-416 CVE-2023-21774: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-21772P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21772 [HIGH] CWE-125 CVE-2023-21772: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-21773P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21773 [HIGH] CWE-416 CVE-2023-21773: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-21885P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.258292022-01-11
CVE-2022-21885 [HIGH] CVE-2022-21885: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
nvd
CVE-2022-21914P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.258292022-01-11
CVE-2022-21914 [HIGH] CVE-2022-21914: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
nvd
CVE-2022-23293P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.258982022-03-09
CVE-2022-23293 [HIGH] CVE-2022-23293: Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-22001P3HIGHCVSS 7.8vsp12022-02-09
CVE-2022-22001 [HIGH] CVE-2022-22001: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
nvd
CVE-2022-29103P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.259542022-05-10
CVE-2022-29103 [HIGH] CVE-2022-29103: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
nvd
CVE-2022-37990P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.261742022-10-11
CVE-2022-37990 [HIGH] CVE-2022-37990: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-26810P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.259242022-04-15
CVE-2022-26810 [HIGH] CVE-2022-26810: Windows File Server Resource Management Service Elevation of Privilege Vulnerability
Windows File Server Resource Management Service Elevation of Privilege Vulnerability
nvd
CVE-2023-21726P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21726 [HIGH] CWE-257 CVE-2023-21726: Windows Credential Manager User Interface Elevation of Privilege Vulnerability
Windows Credential Manager User Interface Elevation of Privilege Vulnerability
nvd
CVE-2023-21754P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21754 [HIGH] CWE-190 CVE-2023-21754: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2020-1554P3HIGHCVSS 7.8≥ 6.1.0, < publication2020-08-17
CVE-2020-1554 [HIGH] CWE-787 CVE-2020-1554: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights.
There are multiple ways an attacker could exploit the vulnerability, such as by convincin
nvd
CVE-2020-1379P3HIGHCVSS 7.8≥ 6.1.0, < publication2020-08-17
CVE-2020-1379 [HIGH] CWE-787 CVE-2020-1379: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights.
There are multiple ways an attacker could exploit the vulnerability, such as by convincin
nvd