Microsoft Windows 7 vulnerabilities
881 known vulnerabilities affecting microsoft/windows_7.
Total CVEs
881
CISA KEV
35
actively exploited
Public exploits
31
Exploited in wild
43
Severity breakdown
CRITICAL25HIGH656MEDIUM198LOW2
Vulnerabilities
Page 39 of 45
CVE-2019-1153MEDIUMCVSS 5.5PoC≥ 6.1.0, < publication2019-08-14
CVE-2019-1153 [MEDIUM] CWE-125 CVE-2019-1153: An information disclosure vulnerability exists when the Microsoft Windows Graphics Component imprope
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a spe
nvd
CVE-2019-1148MEDIUMCVSS 5.5PoC≥ 6.1.0, < publication2019-08-14
CVE-2019-1148 [MEDIUM] CWE-125 CVE-2019-1148: An information disclosure vulnerability exists when the Microsoft Windows Graphics Component imprope
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a spe
nvd
CVE-2019-1014HIGHCVSS 7.0≥ 6.1.0, < publication2019-06-12
CVE-2019-1014 [HIGH] CVE-2019-1014: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vul
nvd
CVE-2019-0907HIGHCVSS 7.8≥ 6.1.0, < publication2019-06-12
CVE-2019-0907 [HIGH] CVE-2019-0907: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd
CVE-2019-0906HIGHCVSS 7.8≥ 6.1.0, < publication2019-06-12
CVE-2019-0906 [HIGH] CWE-129 CVE-2019-0906: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vul
nvd
CVE-2019-0960HIGHCVSS 7.0≥ 6.1.0, < publication2019-06-12
CVE-2019-0960 [HIGH] CVE-2019-0960: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vul
nvd
CVE-2019-0943HIGHCVSS 7.8PoC≥ 6.1.0, < publication2019-06-12
CVE-2019-0943 [HIGH] CVE-2019-0943: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Loc
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).
An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user
nvd
CVE-2019-0908HIGHCVSS 7.8≥ 6.1.0, < publication2019-06-12
CVE-2019-0908 [HIGH] CVE-2019-0908: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd
CVE-2019-1028HIGHCVSS 7.8≥ 6.1.0, < publication2019-06-12
CVE-2019-1028 [HIGH] CVE-2019-1028: An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited th
An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges.
To exploit the vulnerability, an attacker could run a specially crafted application that could exploit the vulnerability. This vulnerability by itself does not allow arbitrary code to be run. Howe
nvd
CVE-2019-0904HIGHCVSS 7.8≥ 6.1.0, < publication2019-06-12
CVE-2019-0904 [HIGH] CVE-2019-0904: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd
CVE-2019-0984HIGHCVSS 7.0≥ 6.1.0, < publication2019-06-12
CVE-2019-0984 [HIGH] CVE-2019-0984: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted appli
nvd
CVE-2019-0888HIGHCVSS 8.8≥ 6.1.0, < publication2019-06-12
CVE-2019-0888 [HIGH] CVE-2019-0888: A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objec
A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with the victim user’s privileges.
An attacker could craft a website that exploits the vulnerability and then convince a victim user to visit the website.
The secu
nvd
CVE-2019-0985HIGHCVSS 7.8≥ 6.1.0, < publication2019-06-12
CVE-2019-0985 [HIGH] CWE-787 CVE-2019-0985: A remote code execution vulnerability exists when the Microsoft Speech API (SAPI) improperly handles
A remote code execution vulnerability exists when the Microsoft Speech API (SAPI) improperly handles text-to-speech (TTS) input. The vulnerability could corrupt memory in a way that enables an attacker to execute arbitrary code in the context of the current user.
To exploit the vulnerability, an attacker would need to convince a user to open a specially
nvd
CVE-2019-1017HIGHCVSS 7.0≥ 6.1.0, < publication2019-06-12
CVE-2019-1017 [HIGH] CVE-2019-1017: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vul
nvd
CVE-2019-0973HIGHCVSS 7.8≥ 6.1.0, < publication2019-06-12
CVE-2019-0973 [HIGH] CWE-20 CVE-2019-0973: An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer f
An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.
A locally authenticated attacker could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new
nvd
CVE-2019-1045HIGHCVSS 7.8≥ 6.1.0, < publication2019-06-12
CVE-2019-1045 [HIGH] CVE-2019-1045: An elevation of privilege vulnerability exists in the way that the Windows Network File System (NFS)
An elevation of privilege vulnerability exists in the way that the Windows Network File System (NFS) handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update addres
nvd
CVE-2019-0905HIGHCVSS 7.8≥ 6.1.0, < publication2019-06-12
CVE-2019-0905 [HIGH] CVE-2019-0905: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd
CVE-2019-0909HIGHCVSS 7.5≥ 6.1.0, < publication2019-06-12
CVE-2019-0909 [HIGH] CVE-2019-0909: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd
CVE-2019-1019HIGHCVSS 8.5PoC≥ 6.1.0, < publication2019-06-12
CVE-2019-1019 [HIGH] CWE-200 CVE-2019-1019: A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the sessio
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.
To exploit this vulnerability, an attacker could send a specially crafted authentication request. An attacker who successfully exploited this vulnerability could access another machine using the original user privileges.
The issue
nvd
CVE-2019-0974HIGHCVSS 7.8≥ 6.1.0, < publication2019-06-12
CVE-2019-0974 [HIGH] CVE-2019-0974: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd