Microsoft Windows 7 vulnerabilities
881 known vulnerabilities affecting microsoft/windows_7.
Total CVEs
881
CISA KEV
35
actively exploited
Public exploits
45
Exploited in wild
50
Severity breakdown
CRITICAL25HIGH656MEDIUM198LOW2
Vulnerabilities
Page 5 of 45
CVE-2018-8450P2HIGHCVSS 8.8v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-11-14
CVE-2018-8450 [HIGH] CWE-404 CVE-2018-8450: A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Win
A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8344P3HIGHCVSS 8.8v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-08-15
CVE-2018-8344 [HIGH] CWE-94 CVE-2018-8344: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Wi
nvd
CVE-2023-21746HIGHCVSS 7.8ExploitedPoC≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21746 [HIGH] Windows NTLM Elevation of Privilege Vulnerability
Windows NTLM Elevation of Privilege Vulnerability
Windows NTLM Elevation of Privilege Vulnerability
cvelistv5
CVE-2020-1074P3HIGHCVSS 7.8≥ 6.1.0, < publication2020-09-11
CVE-2020-1074 [HIGH] CVE-2020-1074: <p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly hand
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd
CVE-2021-36947P2HIGHCVSS 8.8≥ 6.1.0, < 6.1.7601.256852021-08-12
CVE-2021-36947 [HIGH] CVE-2021-36947: Windows Print Spooler Remote Code Execution Vulnerability
Windows Print Spooler Remote Code Execution Vulnerability
nvd
CVE-2018-8349P3HIGHCVSS 8.8v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-08-15
CVE-2018-8349 [HIGH] CWE-502 CVE-2018-8349: A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properl
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 20
nvd
CVE-2018-8494P3HIGHCVSS 8.8v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-10-10
CVE-2018-8494 [HIGH] CWE-611 CVE-2018-8494: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Win
nvd
CVE-2022-44666P3HIGHCVSS 7.8≥ 6.1.0, < 6.1.7601.262662022-12-13
CVE-2022-44666 [HIGH] CVE-2022-44666: Windows Contacts Remote Code Execution Vulnerability
Windows Contacts Remote Code Execution Vulnerability
nvd
CVE-2018-8332P3HIGHCVSS 8.8v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-09-13
CVE-2018-8332 [HIGH] CVE-2018-8332: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability." This affects Windows 7, Microsoft Office, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, Windows Server 2016, Windows
nvd
CVE-2023-21752P3HIGHCVSS 7.1PoC≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21752 [HIGH] CWE-284 CVE-2023-21752: Windows Backup Service Elevation of Privilege Vulnerability
Windows Backup Service Elevation of Privilege Vulnerability
nvd
CVE-2022-34722P2CRITICALCVSS 9.8≥ 6.1.0, < 6.1.7601.261152022-09-13
CVE-2022-34722 [CRITICAL] CVE-2022-34722: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2022-35744P2CRITICALCVSS 9.8≥ 6.1.0, < 6.1.7601.260652023-05-31
CVE-2022-35744 [CRITICAL] CVE-2022-35744: Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
nvd
CVE-2018-8225P3HIGHCVSS 8.1v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-06-14
CVE-2018-8225 [HIGH] CVE-2018-8225: A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it
A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, aka "Windows DNSAPI Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Wi
nvd
CVE-2018-1004P3HIGHCVSS 8.8v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-04-12
CVE-2018-1004 [HIGH] CWE-787 CVE-2018-1004: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Internet Explorer 9, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10.
nvd
CVE-2021-38666P2HIGHCVSS 8.8≥ 6.1.0, < 6.1.7601.257692021-11-10
CVE-2021-38666 [HIGH] CVE-2021-38666: Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2021-33757P2CRITICALCVSS 9.8≥ 6.1.0, < 6.1.7601.256612021-07-14
CVE-2021-33757 [CRITICAL] CVE-2021-33757: Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnerability
Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnerability
nvd
CVE-2021-24077P2CRITICALCVSS 9.8≥ 6.1.0, < publication2021-02-25
CVE-2021-24077 [CRITICAL] CVE-2021-24077: Windows Fax Service Remote Code Execution Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2022-30133P2CRITICALCVSS 9.8≥ 6.1.0, < 6.1.7601.260652022-08-09
CVE-2022-30133 [CRITICAL] CVE-2022-30133: Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
nvd
CVE-2021-1722P2CRITICALCVSS 9.8≥ 6.1.0, < publication2021-02-25
CVE-2021-1722 [CRITICAL] CVE-2021-1722: Windows Fax Service Remote Code Execution Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2019-1212P3CRITICALCVSS 9.8≥ 6.1.0, < publication2019-08-14
CVE-2019-1212 [CRITICAL] CWE-787 CVE-2019-1212: A memory corruption vulnerability exists in the Windows Server DHCP service when processing speciall
A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets. An attacker who successfully exploited the vulnerability could cause the DHCP server service to stop responding.
To exploit the vulnerability, a remote unauthenticated attacker could send a specially crafted packet to an affected DH
nvd