cbcvebase.

Microsoft Windows 7 vulnerabilities

881 known vulnerabilities affecting microsoft/windows_7.

Total CVEs
881
CISA KEV
35
actively exploited
Public exploits
45
Exploited in wild
50
Severity breakdown
CRITICAL25HIGH656MEDIUM198LOW2

Vulnerabilities

Page 4 of 45
CVE-2022-23270P2HIGHCVSS 8.1≥ 6.1.0, < 6.1.7601.259542022-05-10
CVE-2022-23270 [HIGH] CVE-2022-23270: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2020-1337P3HIGHCVSS 7.8PoCvsp1≥ 6.1.0, < publication2020-08-17
CVE-2020-1337 [HIGH] CWE-367 CVE-2020-1337: An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly all An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts wit
nvd
CVE-2021-24074P2CRITICALCVSS 9.8≥ 6.1.0, < publication2021-02-25
CVE-2021-24074 [CRITICAL] CVE-2021-24074: Windows TCP/IP Remote Code Execution Vulnerability Windows TCP/IP Remote Code Execution Vulnerability
nvd
CVE-2021-24094P2CRITICALCVSS 9.8≥ 6.1.0, < publication2021-02-25
CVE-2021-24094 [CRITICAL] CVE-2021-24094: Windows TCP/IP Remote Code Execution Vulnerability Windows TCP/IP Remote Code Execution Vulnerability
nvd
CVE-2018-8397P2HIGHCVSS 8.8v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-08-15
CVE-2018-8397 [HIGH] CVE-2018-8397: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka "GDI+ Remote Code Execution Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.
nvd
CVE-2018-8420P2HIGHCVSS 8.8v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-09-13
CVE-2018-8420 [HIGH] CWE-611 CVE-2018-8420: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 S
nvd
CVE-2018-8410P3HIGHCVSS 7.8PoCv32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-09-13
CVE-2018-8410 [HIGH] CWE-404 CVE-2018-8410: An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles regist An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory, aka "Windows Registry Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Server
nvd
CVE-2022-23285P2HIGHCVSS 8.8≥ 6.1.0, < 6.1.7601.258982022-03-09
CVE-2022-23285 [HIGH] CVE-2022-23285: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2018-8411P3HIGHCVSS 7.8PoCv32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-10-10
CVE-2018-8411 [HIGH] CWE-732 CVE-2018-8411: An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevati An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2019-0943P3HIGHCVSS 7.8PoC≥ 6.1.0, < publication2019-06-12
CVE-2019-0943 [HIGH] CVE-2019-0943: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Loc An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user
nvd
CVE-2012-4786P2CRITICALCVSS 10.0vgold2012-12-12
CVE-2012-4786 [CRITICAL] CWE-94 CVE-2012-4786: The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allow remote attackers to execute arbitrary code via a crafted TrueType Font (TTF) file, aka "TrueType Font Parsing Vulnerability."
nvd
CVE-2021-36936P2CRITICALCVSS 9.8≥ 6.1.0, < 6.1.7601.256852021-08-12
CVE-2021-36936 [CRITICAL] CVE-2021-36936: Windows Print Spooler Remote Code Execution Vulnerability Windows Print Spooler Remote Code Execution Vulnerability
nvd
CVE-2022-21990P2HIGHCVSS 8.8≥ 6.1.0, < 6.1.7601.258982022-03-09
CVE-2022-21990 [HIGH] CVE-2022-21990: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2021-34535P2HIGHCVSS 8.8≥ 6.1.0, < 6.1.7601.256852021-08-12
CVE-2021-34535 [HIGH] CVE-2021-34535: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2022-38044P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.261742022-10-11
CVE-2022-38044 [HIGH] CVE-2022-38044: Windows CD-ROM File System Driver Remote Code Execution Vulnerability Windows CD-ROM File System Driver Remote Code Execution Vulnerability
nvd
CVE-2022-22012P2CRITICALCVSS 9.8≥ 6.1.0, < 6.1.7601.259542022-05-10
CVE-2022-22012 [CRITICAL] CVE-2022-22012: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29130P2CRITICALCVSS 9.8≥ 6.1.0, < 6.1.7601.259542022-05-10
CVE-2022-29130 [CRITICAL] CVE-2022-29130: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2021-43217P2CRITICALCVSS 9.8≥ 6.1.0, < 6.1.7601.257962021-12-15
CVE-2021-43217 [CRITICAL] CVE-2021-43217: Windows Encrypting File System (EFS) Remote Code Execution Vulnerability Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
nvd
CVE-2021-36965P2CRITICALCVSS 9.8≥ 6.1.0, < 6.1.7601.257122021-09-15
CVE-2021-36965 [CRITICAL] CVE-2021-36965: Windows WLAN AutoConfig Service Remote Code Execution Vulnerability Windows WLAN AutoConfig Service Remote Code Execution Vulnerability
nvd
CVE-2018-8256P3HIGHCVSS 8.8v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-11-14
CVE-2018-8256 [HIGH] CVE-2018-8256: A remote code execution vulnerability exists when PowerShell improperly handles specially crafted fi A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka "Microsoft PowerShell Remote Code Execution Vulnerability." This affects Windows RT 8.1, PowerShell Core 6.0, Microsoft.PowerShell.Archive 1.2.2.0, Windows Server 2016, Windows Server 2012, Windows Server 2008 R2, Windows Server 2019, Windows 7, Windows
nvd
Microsoft Windows 7 vulnerabilities | cvebase