cbcvebase.

Microsoft Windows 7 vulnerabilities

881 known vulnerabilities affecting microsoft/windows_7.

Total CVEs
881
CISA KEV
35
actively exploited
Public exploits
45
Exploited in wild
50
Severity breakdown
CRITICAL25HIGH656MEDIUM198LOW2

Vulnerabilities

Page 21 of 45
CVE-2022-22001P3HIGHCVSS 7.8vsp12022-02-09
CVE-2022-22001 [HIGH] CVE-2022-22001: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
nvd
CVE-2022-29103P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.259542022-05-10
CVE-2022-29103 [HIGH] CVE-2022-29103: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
nvd
CVE-2022-37990P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.261742022-10-11
CVE-2022-37990 [HIGH] CVE-2022-37990: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-26810P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.259242022-04-15
CVE-2022-26810 [HIGH] CVE-2022-26810: Windows File Server Resource Management Service Elevation of Privilege Vulnerability Windows File Server Resource Management Service Elevation of Privilege Vulnerability
nvd
CVE-2023-21726P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21726 [HIGH] CWE-257 CVE-2023-21726: Windows Credential Manager User Interface Elevation of Privilege Vulnerability Windows Credential Manager User Interface Elevation of Privilege Vulnerability
nvd
CVE-2023-21754P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21754 [HIGH] CWE-190 CVE-2023-21754: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2020-1554P3HIGHCVSS 7.8≥ 6.1.0, < publication2020-08-17
CVE-2020-1554 [HIGH] CWE-787 CVE-2020-1554: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincin
nvd
CVE-2020-1379P3HIGHCVSS 7.8≥ 6.1.0, < publication2020-08-17
CVE-2020-1379 [HIGH] CWE-787 CVE-2020-1379: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincin
nvd
CVE-2020-17044P3HIGHCVSS 7.8≥ 6.1.0, < publication2020-11-11
CVE-2020-17044 [HIGH] CVE-2020-17044: Windows Remote Access Elevation of Privilege Vulnerability Windows Remote Access Elevation of Privilege Vulnerability
nvd
CVE-2020-17043P3HIGHCVSS 7.8≥ 6.1.0, < publication2020-11-11
CVE-2020-17043 [HIGH] CVE-2020-17043: Windows Remote Access Elevation of Privilege Vulnerability Windows Remote Access Elevation of Privilege Vulnerability
nvd
CVE-2022-37985P4MEDIUMCVSS 5.5≥ 6.1.0, < 6.1.7601.261742022-10-11
CVE-2022-37985 [MEDIUM] CVE-2022-37985: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2020-16920P3HIGHCVSS 7.8≥ 6.1.0, < publication2020-10-16
CVE-2020-16920 [HIGH] CVE-2020-16920: <p>An elevation of privilege vulnerability exists when the Windows Application Compatibility Client An elevation of privilege vulnerability exists when the Windows Application Compatibility Client Library improperly handles registry operations. An attacker who successfully exploited this vulnerability could gain elevated privileges. To exploit the vulnerability, an attacker would first need code execution on a victim system. An attacker could then run a spec
nvd
CVE-2022-30166P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.259842022-06-15
CVE-2022-30166 [HIGH] CVE-2022-30166: Local Security Authority Subsystem Service Elevation of Privilege Vulnerability Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
nvd
CVE-2021-26862P3HIGHCVSS 7.8≥ 6.1.0, < publication2021-03-11
CVE-2021-26862 [HIGH] CWE-59 CVE-2021-26862: Windows Installer Elevation of Privilege Vulnerability Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2020-1475P3HIGHCVSS 7.8≥ 6.1.0, < publication2020-08-17
CVE-2020-1475 [HIGH] CVE-2020-1475: An elevation of privilege vulnerability exists in the way that the srmsvc.dll handles objects in mem An elevation of privilege vulnerability exists in the way that the srmsvc.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addresses the vulnerability b
nvd
CVE-2022-38004P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.261152022-09-13
CVE-2022-38004 [HIGH] CVE-2022-38004: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2019-0973P3HIGHCVSS 7.8≥ 6.1.0, < publication2019-06-12
CVE-2019-0973 [HIGH] CWE-20 CVE-2019-0973: An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer f An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior. A locally authenticated attacker could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new
nvd
CVE-2022-41121P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.262662022-12-13
CVE-2022-41121 [HIGH] CVE-2022-41121: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2022-34719P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.261152022-09-13
CVE-2022-34719 [HIGH] CVE-2022-34719: Windows Distributed File System (DFS) Elevation of Privilege Vulnerability Windows Distributed File System (DFS) Elevation of Privilege Vulnerability
nvd
CVE-2020-0782P3HIGHCVSS 7.8≥ 6.1.0, < publication2020-09-11
CVE-2020-0782 [HIGH] CVE-2020-0782: <p>An elevation of privilege vulnerability exists when the Windows Cryptographic Catalog Services im An elevation of privilege vulnerability exists when the Windows Cryptographic Catalog Services improperly handle objects in memory. An attacker who successfully exploited this vulnerability could modify the cryptographic catalog. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted a
nvd
Microsoft Windows 7 vulnerabilities | cvebase