cbcvebase.

Microsoft Windows 7 vulnerabilities

906 known vulnerabilities affecting microsoft/windows_7.

Total CVEs
906
CISA KEV
36
actively exploited
Public exploits
47
Exploited in wild
53
Severity breakdown
CRITICAL26HIGH674MEDIUM204LOW2

Vulnerabilities

Page 22 of 46
CVE-2020-1150P3HIGHCVSS 7.8≥ 6.1.0, < publication2020-05-21
CVE-2020-1150 [HIGH] CWE-787 CVE-2020-1150: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincin
nvd
CVE-2022-37985P4MEDIUMCVSS 5.5≥ 6.1.0, < 6.1.7601.261742022-10-11
CVE-2022-37985 [MEDIUM] CVE-2022-37985: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2021-1734P3HIGHCVSS 7.5≥ 6.1.0, < publication2021-02-25
CVE-2021-1734 [HIGH] CVE-2021-1734: Windows Remote Procedure Call Information Disclosure Vulnerability Windows Remote Procedure Call Information Disclosure Vulnerability
nvd
CVE-2022-35743P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.260652023-05-31
CVE-2022-35743 [HIGH] CWE-94 CVE-2022-35743: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
nvd
CVE-2021-27077P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.245662021-03-11
CVE-2021-27077 [HIGH] CWE-269 CVE-2021-27077: Windows Win32k Elevation of Privilege Vulnerability Windows Win32k Elevation of Privilege Vulnerability
nvd
CVE-2020-16920P3HIGHCVSS 7.8≥ 6.1.0, < publication2020-10-16
CVE-2020-16920 [HIGH] CVE-2020-16920: <p>An elevation of privilege vulnerability exists when the Windows Application Compatibility Client An elevation of privilege vulnerability exists when the Windows Application Compatibility Client Library improperly handles registry operations. An attacker who successfully exploited this vulnerability could gain elevated privileges. To exploit the vulnerability, an attacker would first need code execution on a victim system. An attacker could then run a spec
nvd
CVE-2022-30166P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.259842022-06-15
CVE-2022-30166 [HIGH] CVE-2022-30166: Local Security Authority Subsystem Service Elevation of Privilege Vulnerability Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
nvd
CVE-2021-26862P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.245662021-03-11
CVE-2021-26862 [HIGH] CWE-59 CVE-2021-26862: Windows Installer Elevation of Privilege Vulnerability Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2020-1475P3HIGHCVSS 7.8≥ 6.1.0, < publication2020-08-17
CVE-2020-1475 [HIGH] CVE-2020-1475: An elevation of privilege vulnerability exists in the way that the srmsvc.dll handles objects in mem An elevation of privilege vulnerability exists in the way that the srmsvc.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addresses the vulnerability b
nvd
CVE-2021-26873P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.245662021-03-11
CVE-2021-26873 [HIGH] CWE-59 CVE-2021-26873: Windows User Profile Service Elevation of Privilege Vulnerability Windows User Profile Service Elevation of Privilege Vulnerability
nvd
CVE-2020-1070P3HIGHCVSS 7.8≥ 6.1.0, < publication2020-05-21
CVE-2020-1070 [HIGH] CVE-2020-1070: An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly all An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full u
nvd
CVE-2022-38004P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.261152022-09-13
CVE-2022-38004 [HIGH] CVE-2022-38004: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2022-34719P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.261152022-09-13
CVE-2022-34719 [HIGH] CVE-2022-34719: Windows Distributed File System (DFS) Elevation of Privilege Vulnerability Windows Distributed File System (DFS) Elevation of Privilege Vulnerability
nvd
CVE-2021-26887P3HIGHCVSS 7.8v-2021-03-11
CVE-2021-26887 [HIGH] CWE-59 CVE-2021-26887: An elevation of privilege vulnerability exists in Microsoft Windows when Folder redirection has been An elevation of privilege vulnerability exists in Microsoft Windows when Folder redirection has been enabled via Group Policy. When folder redirection file server is co-located with Terminal server, an attacker who successfully exploited the vulnerability would be able to begin redirecting another user's personal data to a created folder. To exploit th
nvd
CVE-2019-0973P3HIGHCVSS 7.8≥ 6.1.0, < publication2019-06-12
CVE-2019-0973 [HIGH] CWE-20 CVE-2019-0973: An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer f An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior. A locally authenticated attacker could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new
nvd
CVE-2022-41121P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.262662022-12-13
CVE-2022-41121 [HIGH] CVE-2022-41121: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2021-34537P3HIGHCVSS 8.0≥ 6.1.0, < 6.1.7601.256852021-08-12
CVE-2021-34537 [HIGH] CWE-269 CVE-2021-34537: Windows Bluetooth Driver Elevation of Privilege Vulnerability Windows Bluetooth Driver Elevation of Privilege Vulnerability
nvd
CVE-2020-1486P3HIGHCVSS 7.8≥ 6.1.0, < publication2020-08-17
CVE-2020-1486 [HIGH] CVE-2020-1486: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, a
nvd
CVE-2020-1010P3HIGHCVSS 7.8≥ 6.1.0, < publication2020-05-21
CVE-2020-1010 [HIGH] CVE-2020-1010: An elevation of privilege vulnerability exists in Windows Block Level Backup Engine Service (wbengin An elevation of privilege vulnerability exists in Windows Block Level Backup Engine Service (wbengine) that allows file deletion in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affecte
nvd
CVE-2021-26899P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.245662021-03-11
CVE-2021-26899 [HIGH] CVE-2021-26899: Windows UPnP Device Host Elevation of Privilege Vulnerability Windows UPnP Device Host Elevation of Privilege Vulnerability
nvd
Microsoft Windows 7 vulnerabilities | cvebase