cbcvebase.

Microsoft Windows 7 vulnerabilities

906 known vulnerabilities affecting microsoft/windows_7.

Total CVEs
906
CISA KEV
36
actively exploited
Public exploits
47
Exploited in wild
53
Severity breakdown
CRITICAL26HIGH674MEDIUM204LOW2

Vulnerabilities

Page 33 of 46
CVE-2021-38665P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.257692021-11-10
CVE-2021-38665 [MEDIUM] CVE-2021-38665: Remote Desktop Protocol Client Information Disclosure Vulnerability Remote Desktop Protocol Client Information Disclosure Vulnerability
nvd
CVE-2021-31968P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.256322021-06-08
CVE-2021-31968 [HIGH] CVE-2021-31968: Windows Remote Desktop Services Denial of Service Vulnerability Windows Remote Desktop Services Denial of Service Vulnerability
nvd
CVE-2022-21889P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.258292022-01-11
CVE-2022-21889 [HIGH] CVE-2022-21889: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2022-21890P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.258292022-01-11
CVE-2022-21890 [HIGH] CVE-2022-21890: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2022-33645P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.261742022-10-11
CVE-2022-33645 [HIGH] CVE-2022-33645: Windows TCP/IP Driver Denial of Service Vulnerability Windows TCP/IP Driver Denial of Service Vulnerability
nvd
CVE-2022-38041P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.261742022-10-11
CVE-2022-38041 [HIGH] CVE-2022-38041: Windows Secure Channel Denial of Service Vulnerability Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2022-41058P3HIGHCVSS 7.5vsp1≥ 6.1.0, < 6.1.7601.262212022-11-09
CVE-2022-41058 [HIGH] CVE-2022-41058: Windows Network Address Translation (NAT) Denial of Service Vulnerability Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2023-21757P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21757 [HIGH] CWE-476 CVE-2023-21757: Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability
nvd
CVE-2018-8304P3MEDIUMCVSS 5.9v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-07-11
CVE-2018-8304 [MEDIUM] CVE-2018-8304: A denial of service vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fail A denial of service vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, aka "Windows DNSAPI Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows
nvd
CVE-2020-16997P3MEDIUMCVSS 6.5vsp1≥ 6.1.0, < publication2020-11-11
CVE-2020-16997 [MEDIUM] CVE-2020-16997: Remote Desktop Protocol Server Information Disclosure Vulnerability Remote Desktop Protocol Server Information Disclosure Vulnerability
nvd
CVE-2021-43216P3MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.257962021-12-15
CVE-2021-43216 [MEDIUM] CWE-668 CVE-2021-43216: Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
nvd
CVE-2018-8422P4MEDIUMCVSS 6.5v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-09-13
CVE-2018-8422 [MEDIUM] CWE-200 CVE-2018-8422: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8424.
nvd
CVE-2023-21527P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21527 [HIGH] CWE-191 CVE-2023-21527: Windows iSCSI Service Denial of Service Vulnerability Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2022-38042P3HIGHCVSS 7.1≥ 6.1.0, < 6.1.7601.261742022-10-11
CVE-2022-38042 [HIGH] CVE-2022-38042: Active Directory Domain Services Elevation of Privilege Vulnerability Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2022-26936P3MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.259542022-05-10
CVE-2022-26936 [MEDIUM] CVE-2022-26936: Windows Server Service Information Disclosure Vulnerability Windows Server Service Information Disclosure Vulnerability
nvd
CVE-2019-1043P4MEDIUMCVSS 6.4≥ 6.1.0, < publication2019-06-12
CVE-2019-1043 [MEDIUM] CVE-2019-1043: A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current
nvd
CVE-2019-1014P4HIGHCVSS 7.0≥ 6.1.0, < publication2019-06-12
CVE-2019-1014 [HIGH] CVE-2019-1014: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vul
nvd
CVE-2019-0960P4HIGHCVSS 7.0≥ 6.1.0, < publication2019-06-12
CVE-2019-0960 [HIGH] CVE-2019-0960: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vul
nvd
CVE-2019-1017P4HIGHCVSS 7.0≥ 6.1.0, < publication2019-06-12
CVE-2019-1017 [HIGH] CVE-2019-1017: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vul
nvd
CVE-2022-23298P4HIGHCVSS 7.0≥ 6.1.0, < 6.1.7601.258982022-03-09
CVE-2022-23298 [HIGH] CVE-2022-23298: Windows NT OS Kernel Elevation of Privilege Vulnerability Windows NT OS Kernel Elevation of Privilege Vulnerability
nvd
Microsoft Windows 7 vulnerabilities | cvebase