cbcvebase.

Microsoft Windows 7 vulnerabilities

881 known vulnerabilities affecting microsoft/windows_7.

Total CVEs
881
CISA KEV
35
actively exploited
Public exploits
45
Exploited in wild
50
Severity breakdown
CRITICAL25HIGH656MEDIUM198LOW2

Vulnerabilities

Page 34 of 45
CVE-2023-21750P4HIGHCVSS 7.1≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21750 [HIGH] CWE-284 CVE-2023-21750: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2019-1178P4HIGHCVSS 7.0≥ 6.1.0, < publication2019-08-14
CVE-2019-1178 [HIGH] CVE-2019-1178: An elevation of privilege vulnerability exists in the way that the ssdpsrv.dll handles objects in me An elevation of privilege vulnerability exists in the way that the ssdpsrv.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addresses the vulnerability
nvd
CVE-2022-30225P4HIGHCVSS 7.1≥ 6.1.0, < 6.1.7601.260222022-07-12
CVE-2022-30225 [HIGH] CVE-2022-30225: Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability
nvd
CVE-2019-1177P4HIGHCVSS 7.0≥ 6.1.0, < publication2019-08-14
CVE-2019-1177 [HIGH] CWE-269 CVE-2019-1177: An elevation of privilege vulnerability exists in the way that the rpcss.dll handles objects in memo An elevation of privilege vulnerability exists in the way that the rpcss.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addresses the vulnerab
nvd
CVE-2022-26807P4HIGHCVSS 7.0≥ 6.1.0, < 6.1.7601.259242022-04-15
CVE-2022-26807 [HIGH] CWE-362 CVE-2022-26807: Windows Work Folder Service Elevation of Privilege Vulnerability Windows Work Folder Service Elevation of Privilege Vulnerability
nvd
CVE-2023-21542P4HIGHCVSS 7.0≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21542 [HIGH] CWE-59 CVE-2023-21542: Windows Installer Elevation of Privilege Vulnerability Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2022-30205P4MEDIUMCVSS 6.6≥ 6.1.0, < 6.1.7601.260222022-07-12
CVE-2022-30205 [MEDIUM] CWE-362 CVE-2022-30205: Windows Group Policy Elevation of Privilege Vulnerability Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2022-21924P4MEDIUMCVSS 5.3≥ 6.1.0, < 6.1.7601.258292022-01-11
CVE-2022-21924 [MEDIUM] CVE-2022-21924: Workstation Service Remote Protocol Security Feature Bypass Vulnerability Workstation Service Remote Protocol Security Feature Bypass Vulnerability
nvd
CVE-2018-1040P4MEDIUMCVSS 5.3v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-06-14
CVE-2018-1040 [MEDIUM] CVE-2018-1040: A denial of service vulnerability exists in the way that the Windows Code Integrity Module performs A denial of service vulnerability exists in the way that the Windows Code Integrity Module performs hashing, aka "Windows Code Integrity Module Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows
nvd
CVE-2021-34507P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.256612021-07-14
CVE-2021-34507 [MEDIUM] CVE-2021-34507: Windows Remote Assistance Information Disclosure Vulnerability Windows Remote Assistance Information Disclosure Vulnerability
nvd
CVE-2022-26934P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.259542022-05-10
CVE-2022-26934 [MEDIUM] CVE-2022-26934: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2020-17014P4HIGHCVSS 7.1vsp1≥ 6.1.0, < publication2020-11-11
CVE-2020-17014 [HIGH] CVE-2020-17014: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-30208P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.260222022-07-12
CVE-2022-30208 [MEDIUM] CVE-2022-30208: Windows Security Account Manager (SAM) Denial of Service Vulnerability Windows Security Account Manager (SAM) Denial of Service Vulnerability
nvd
CVE-2018-8224P4HIGHCVSS 7.0v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-06-14
CVE-2018-8224 [HIGH] CWE-404 CVE-2018-8224: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.
nvd
CVE-2018-8169P4HIGHCVSS 7.0v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-06-14
CVE-2018-8169 [HIGH] CWE-404 CVE-2018-8169: An elevation of privilege vulnerability exists when the (Human Interface Device) HID Parser Library An elevation of privilege vulnerability exists when the (Human Interface Device) HID Parser Library driver improperly handles objects in memory, aka "HIDParser Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 20
nvd
CVE-2018-8339P4HIGHCVSS 7.0v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-08-15
CVE-2018-8339 [HIGH] CWE-20 CVE-2018-8339: An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer f An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior, aka "Windows Installer Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows
nvd
CVE-2018-8399P4HIGHCVSS 7.0v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-08-15
CVE-2018-8399 [HIGH] CWE-404 CVE-2018-8399: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID is unique from CVE-2018-8404.
nvd
CVE-2018-1036P4HIGHCVSS 7.0v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-06-14
CVE-2018-1036 [HIGH] CWE-732 CVE-2018-1036: An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevati An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2022-21997P4HIGHCVSS 7.1vsp1≥ 6.1.0, < 6.1.7601.258602022-02-09
CVE-2022-21997 [HIGH] CWE-59 CVE-2022-21997: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-22022P4HIGHCVSS 7.1≥ 6.1.0, < 6.1.7601.260222022-07-12
CVE-2022-22022 [HIGH] CVE-2022-22022: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
Microsoft Windows 7 vulnerabilities | cvebase