cbcvebase.

Microsoft Windows 7 vulnerabilities

881 known vulnerabilities affecting microsoft/windows_7.

Total CVEs
881
CISA KEV
35
actively exploited
Public exploits
45
Exploited in wild
50
Severity breakdown
CRITICAL25HIGH656MEDIUM198LOW2

Vulnerabilities

Page 35 of 45
CVE-2022-30226P4HIGHCVSS 7.1≥ 6.1.0, < 6.1.7601.260222022-07-12
CVE-2022-30226 [HIGH] CVE-2022-30226: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-35837P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.261152022-09-13
CVE-2022-35837 [MEDIUM] CVE-2022-35837: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2022-34690P4HIGHCVSS 7.1≥ 6.1.0, < 6.1.7601.260652022-08-09
CVE-2022-34690 [HIGH] CVE-2022-34690: Windows Fax Service Elevation of Privilege Vulnerability Windows Fax Service Elevation of Privilege Vulnerability
nvd
CVE-2023-21760P4HIGHCVSS 7.1≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21760 [HIGH] CWE-59 CVE-2023-21760: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-38006P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.261152022-09-13
CVE-2022-38006 [MEDIUM] CVE-2022-38006: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2018-0976P4MEDIUMCVSS 5.3v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-04-12
CVE-2018-0976 [MEDIUM] CVE-2018-0976: A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka "Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.
nvd
CVE-2022-37977P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.261742022-10-11
CVE-2022-37977 [MEDIUM] CVE-2022-37977: Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
nvd
CVE-2023-21560P4MEDIUMCVSS 6.6≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21560 [MEDIUM] CWE-122 CVE-2023-21560: Windows Boot Manager Security Feature Bypass Vulnerability Windows Boot Manager Security Feature Bypass Vulnerability
nvd
CVE-2019-0716P4MEDIUMCVSS 5.8≥ 6.1.0, < publication2019-08-14
CVE-2019-0716 [MEDIUM] CVE-2019-0716: A denial of service vulnerability exists when Windows improperly handles objects in memory. An attac A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an
nvd
CVE-2018-8167P4HIGHCVSS 7.0v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-05-09
CVE-2018-8167 [HIGH] CWE-404 CVE-2018-8167: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka "Windows Common Log File System Driver Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server
nvd
CVE-2022-35759P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.260652023-05-31
CVE-2022-35759 [MEDIUM] CVE-2022-35759: Windows Local Security Authority (LSA) Denial of Service Vulnerability Windows Local Security Authority (LSA) Denial of Service Vulnerability
nvd
CVE-2022-38032P4MEDIUMCVSS 6.6≥ 6.1.0, < 6.1.7601.261742022-10-11
CVE-2022-38032 [MEDIUM] CVE-2022-38032: Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability
nvd
CVE-2022-22023P4MEDIUMCVSS 6.6≥ 6.1.0, < 6.1.7601.260222022-07-12
CVE-2022-22023 [MEDIUM] CVE-2022-22023: Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability
nvd
CVE-2019-0968P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2019-06-12
CVE-2019-0968 [MEDIUM] CVE-2019-0968: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a spe
nvd
CVE-2019-1013P4MEDIUMCVSS 4.7≥ 6.1.0, < publication2019-06-12
CVE-2019-1013 [MEDIUM] CWE-200 CVE-2019-1013: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2019-1053P4MEDIUMCVSS 6.3≥ 6.1.0, < publication2019-06-12
CVE-2019-1053 [MEDIUM] CWE-59 CVE-2019-1053: An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder short An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the vulnerability could elevate privileges by escaping a sandbox. To exploit this vulnerability, an attacker would require unprivileged execution on the victim system. The security update addresses the vulnera
nvd
CVE-2020-16914P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2020-10-16
CVE-2020-16914 [MEDIUM] CVE-2020-16914: <p>An information disclosure vulnerability exists in the way that the Windows Graphics Device Interf An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface Plus (GDI+) handles objects in memory, allowing an attacker to retrieve information from a targeted system. By itself, the information disclosure does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses i
nvd
CVE-2021-43224P4MEDIUMCVSS 5.5≥ 6.1.0, < 6.1.7601.257962021-12-15
CVE-2021-43224 [MEDIUM] CVE-2021-43224: Windows Common Log File System Driver Information Disclosure Vulnerability Windows Common Log File System Driver Information Disclosure Vulnerability
nvd
CVE-2019-1187P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2019-08-14
CVE-2019-1187 [MEDIUM] CWE-611 CVE-2019-1187: A denial of service vulnerability exists when the XmlLite runtime (XmlLite.dll) improperly parses XM A denial of service vulnerability exists when the XmlLite runtime (XmlLite.dll) improperly parses XML input. An attacker who successfully exploited this vulnerability could cause a denial of service against an XML application. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to an XML application
nvd
CVE-2022-41086P4MEDIUMCVSS 6.4vsp1≥ 6.1.0, < 6.1.7601.262212022-11-09
CVE-2022-41086 [MEDIUM] CWE-362 CVE-2022-41086: Windows Group Policy Elevation of Privilege Vulnerability Windows Group Policy Elevation of Privilege Vulnerability
nvd
Microsoft Windows 7 vulnerabilities | cvebase