Microsoft Windows 7 vulnerabilities
906 known vulnerabilities affecting microsoft/windows_7.
Total CVEs
906
CISA KEV
36
actively exploited
Public exploits
47
Exploited in wild
53
Severity breakdown
CRITICAL26HIGH674MEDIUM204LOW2
Vulnerabilities
Page 32 of 46
CVE-2018-8394P3MEDIUMCVSS 6.5v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-08-15
CVE-2018-8394 [MEDIUM] CWE-200 CVE-2018-8394: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Window
nvd
CVE-2019-5921P3HIGHCVSS 7.8vunspecified2019-03-12
CVE-2019-5921 [HIGH] CWE-426 CVE-2019-5921: Untrusted search path vulnerability in Windows 7 allows an attacker to gain privileges via a Trojan
Untrusted search path vulnerability in Windows 7 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
nvd
CVE-2022-21883P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.258292022-01-11
CVE-2022-21883 [HIGH] CVE-2022-21883: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2022-21848P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.258292022-01-11
CVE-2022-21848 [HIGH] CVE-2022-21848: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2021-31183P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.256612021-07-14
CVE-2021-31183 [HIGH] CVE-2021-31183: Windows TCP/IP Driver Denial of Service Vulnerability
Windows TCP/IP Driver Denial of Service Vulnerability
nvd
CVE-2022-34720P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.261152022-09-13
CVE-2022-34720 [HIGH] CVE-2022-34720: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2022-26915P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.259242022-04-15
CVE-2022-26915 [HIGH] CVE-2022-26915: Windows Secure Channel Denial of Service Vulnerability
Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2019-0972P3MEDIUMCVSS 6.5≥ 6.1.0, < publication2019-06-12
CVE-2019-0972 [MEDIUM] CVE-2019-0972: This security update corrects a denial of service in the Local Security Authority Subsystem Service
This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could cause a denial of service on the target system's LSASS service, which triggers an automatic rebo
nvd
CVE-2022-30202P3HIGHCVSS 7.0≥ 6.1.0, < 6.1.7601.260222022-07-12
CVE-2022-30202 [HIGH] CVE-2022-30202: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
nvd
CVE-2022-35833P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.261152022-09-13
CVE-2022-35833 [HIGH] CVE-2022-35833: Windows Secure Channel Denial of Service Vulnerability
Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2022-30152P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.259842022-06-15
CVE-2022-30152 [HIGH] CVE-2022-30152: Windows Network Address Translation (NAT) Denial of Service Vulnerability
Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2022-34701P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.260652022-08-09
CVE-2022-34701 [HIGH] CWE-400 CVE-2022-34701: Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
nvd
CVE-2020-1179P3MEDIUMCVSS 6.5≥ 6.1.0, < publication2020-05-21
CVE-2020-1179 [MEDIUM] CVE-2020-1179: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a spe
nvd
CVE-2022-35769P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.260652022-08-09
CVE-2022-35769 [HIGH] CWE-400 CVE-2022-35769: Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
nvd
CVE-2020-0963P3MEDIUMCVSS 6.5≥ 6.1.0, < publication2020-05-21
CVE-2020-0963 [MEDIUM] CVE-2020-0963: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a spe
nvd
CVE-2020-1256P3MEDIUMCVSS 6.5≥ 6.1.0, < publication2020-09-11
CVE-2020-1256 [MEDIUM] CVE-2020-1256: <p>An information disclosure vulnerability exists when the Windows GDI component improperly disclose
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a spe
nvd
CVE-2020-1097P3MEDIUMCVSS 6.5≥ 6.1.0, < publication2020-09-11
CVE-2020-1097 [MEDIUM] CVE-2020-1097: <p>An information disclosure vulnerability exists when the Windows GDI component improperly disclose
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a speci
nvd
CVE-2020-1091P3MEDIUMCVSS 6.5≥ 6.1.0, < publication2020-09-11
CVE-2020-1091 [MEDIUM] CVE-2020-1091: <p>An information disclosure vulnerability exists when the Windows GDI component improperly disclose
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a speci
nvd
CVE-2018-8308P3MEDIUMCVSS 6.6v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-07-11
CVE-2018-8308 [MEDIUM] CWE-404 CVE-2018-8308: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Win
nvd
CVE-2022-22040P3HIGHCVSS 7.3≥ 6.1.0, < 6.1.7601.260222022-07-12
CVE-2022-22040 [HIGH] CVE-2022-22040: Internet Information Services Dynamic Compression Module Denial of Service Vulnerability
Internet Information Services Dynamic Compression Module Denial of Service Vulnerability
nvd