Microsoft Windows 7 vulnerabilities
906 known vulnerabilities affecting microsoft/windows_7.
Total CVEs
906
CISA KEV
36
actively exploited
Public exploits
47
Exploited in wild
53
Severity breakdown
CRITICAL26HIGH674MEDIUM204LOW2
Vulnerabilities
Page 35 of 46
CVE-2018-1036P4HIGHCVSS 7.0v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-06-14
CVE-2018-1036 [HIGH] CWE-732 CVE-2018-1036: An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevati
An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2023-21750P4HIGHCVSS 7.1≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21750 [HIGH] CWE-284 CVE-2023-21750: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2019-0984P4HIGHCVSS 7.0≥ 6.1.0, < publication2019-06-12
CVE-2019-0984 [HIGH] CVE-2019-0984: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted appli
nvd
CVE-2022-34690P4HIGHCVSS 7.1≥ 6.1.0, < 6.1.7601.260652022-08-09
CVE-2022-34690 [HIGH] CVE-2022-34690: Windows Fax Service Elevation of Privilege Vulnerability
Windows Fax Service Elevation of Privilege Vulnerability
nvd
CVE-2019-1178P4HIGHCVSS 7.0≥ 6.1.0, < publication2019-08-14
CVE-2019-1178 [HIGH] CVE-2019-1178: An elevation of privilege vulnerability exists in the way that the ssdpsrv.dll handles objects in me
An elevation of privilege vulnerability exists in the way that the ssdpsrv.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update addresses the vulnerability
nvd
CVE-2022-30225P4HIGHCVSS 7.1≥ 6.1.0, < 6.1.7601.260222022-07-12
CVE-2022-30225 [HIGH] CVE-2022-30225: Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability
Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability
nvd
CVE-2019-1177P4HIGHCVSS 7.0≥ 6.1.0, < publication2019-08-14
CVE-2019-1177 [HIGH] CWE-269 CVE-2019-1177: An elevation of privilege vulnerability exists in the way that the rpcss.dll handles objects in memo
An elevation of privilege vulnerability exists in the way that the rpcss.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update addresses the vulnerab
nvd
CVE-2020-1071P4MEDIUMCVSS 6.8≥ 6.1.0, < publication2020-05-21
CVE-2020-1071 [MEDIUM] CWE-755 CVE-2020-1071: An elevation of privilege vulnerability exists when Windows improperly handles errors tied to Remote
An elevation of privilege vulnerability exists when Windows improperly handles errors tied to Remote Access Common Dialog. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges.
To exploit this vulnerability an attacker would need to physically access the booted machine to reach the logon screen. An
nvd
CVE-2022-26807P4HIGHCVSS 7.0≥ 6.1.0, < 6.1.7601.259242022-04-15
CVE-2022-26807 [HIGH] CWE-362 CVE-2022-26807: Windows Work Folder Service Elevation of Privilege Vulnerability
Windows Work Folder Service Elevation of Privilege Vulnerability
nvd
CVE-2019-0986P4MEDIUMCVSS 6.3≥ 6.1.0, < publication2019-06-12
CVE-2019-0986 [MEDIUM] CWE-59 CVE-2019-0986: An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) impro
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a spe
nvd
CVE-2023-21542P4HIGHCVSS 7.0≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21542 [HIGH] CWE-59 CVE-2023-21542: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2022-21924P4MEDIUMCVSS 5.3≥ 6.1.0, < 6.1.7601.258292022-01-11
CVE-2022-21924 [MEDIUM] CVE-2022-21924: Workstation Service Remote Protocol Security Feature Bypass Vulnerability
Workstation Service Remote Protocol Security Feature Bypass Vulnerability
nvd
CVE-2018-1040P4MEDIUMCVSS 5.3v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-06-14
CVE-2018-1040 [MEDIUM] CVE-2018-1040: A denial of service vulnerability exists in the way that the Windows Code Integrity Module performs
A denial of service vulnerability exists in the way that the Windows Code Integrity Module performs hashing, aka "Windows Code Integrity Module Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows
nvd
CVE-2021-34507P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.256612021-07-14
CVE-2021-34507 [MEDIUM] CVE-2021-34507: Windows Remote Assistance Information Disclosure Vulnerability
Windows Remote Assistance Information Disclosure Vulnerability
nvd
CVE-2022-29112P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.259542022-05-10
CVE-2022-29112 [MEDIUM] CVE-2022-29112: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2022-26934P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.259542022-05-10
CVE-2022-26934 [MEDIUM] CVE-2022-26934: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2022-35837P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.261152022-09-13
CVE-2022-35837 [MEDIUM] CVE-2022-35837: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2022-30208P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.260222022-07-12
CVE-2022-30208 [MEDIUM] CVE-2022-30208: Windows Security Account Manager (SAM) Denial of Service Vulnerability
Windows Security Account Manager (SAM) Denial of Service Vulnerability
nvd
CVE-2018-1008P4HIGHCVSS 7.0v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-04-12
CVE-2018-1008 [HIGH] CVE-2018-1008: An elevation of privilege vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD.dll)
An elevation of privilege vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD.dll) when it fails to properly handle objects in memory, aka "OpenType Font Driver Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windo
nvd
CVE-2018-8339P4HIGHCVSS 7.0v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-08-15
CVE-2018-8339 [HIGH] CWE-20 CVE-2018-8339: An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer f
An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior, aka "Windows Installer Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows
nvd