Microsoft Windows 7 Service Pack 1 vulnerabilities
817 known vulnerabilities affecting microsoft/windows_7_service_pack_1.
Total CVEs
817
CISA KEV
28
actively exploited
Public exploits
34
Exploited in wild
40
Severity breakdown
CRITICAL25HIGH615MEDIUM176LOW1
Vulnerabilities
Page 30 of 41
CVE-2022-33645P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.261742022-10-11
CVE-2022-33645 [HIGH] CVE-2022-33645: Windows TCP/IP Driver Denial of Service Vulnerability
Windows TCP/IP Driver Denial of Service Vulnerability
nvd
CVE-2023-21757P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21757 [HIGH] CWE-476 CVE-2023-21757: Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability
Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability
nvd
CVE-2022-38041P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.261742022-10-11
CVE-2022-38041 [HIGH] CVE-2022-38041: Windows Secure Channel Denial of Service Vulnerability
Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2020-1091P3MEDIUMCVSS 6.5≥ 6.1.0, < publication2020-09-11
CVE-2020-1091 [MEDIUM] CVE-2020-1091: <p>An information disclosure vulnerability exists when the Windows GDI component improperly disclose
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a speci
nvd
CVE-2022-35769P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.260652022-08-09
CVE-2022-35769 [HIGH] CWE-400 CVE-2022-35769: Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
nvd
CVE-2022-41058P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.262212022-11-09
CVE-2022-41058 [HIGH] CVE-2022-41058: Windows Network Address Translation (NAT) Denial of Service Vulnerability
Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2020-16997P4MEDIUMCVSS 6.5≥ 6.1.0, < publication2020-11-11
CVE-2020-16997 [MEDIUM] CVE-2020-16997: Remote Desktop Protocol Server Information Disclosure Vulnerability
Remote Desktop Protocol Server Information Disclosure Vulnerability
nvd
CVE-2021-43216P3MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.257962021-12-15
CVE-2021-43216 [MEDIUM] CWE-668 CVE-2021-43216: Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
nvd
CVE-2021-38665P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.257692021-11-10
CVE-2021-38665 [MEDIUM] CVE-2021-38665: Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability
nvd
CVE-2019-1025P3MEDIUMCVSS 6.5≥ 6.1.0, < publication2019-06-12
CVE-2019-1025 [MEDIUM] CVE-2019-1025: A denial of service vulnerability exists when Windows improperly handles objects in memory. An attac
A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application or to convince a user to open a specif
nvd
CVE-2023-21527P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21527 [HIGH] CWE-191 CVE-2023-21527: Windows iSCSI Service Denial of Service Vulnerability
Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2022-38042P3HIGHCVSS 7.1≥ 6.1.0, < 6.1.7601.261742022-10-11
CVE-2022-38042 [HIGH] CVE-2022-38042: Active Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2022-26936P3MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.259542022-05-10
CVE-2022-26936 [MEDIUM] CVE-2022-26936: Windows Server Service Information Disclosure Vulnerability
Windows Server Service Information Disclosure Vulnerability
nvd
CVE-2019-1043P4MEDIUMCVSS 6.4≥ 6.1.0, < publication2019-06-12
CVE-2019-1043 [MEDIUM] CVE-2019-1043: A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory.
A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current
nvd
CVE-2022-22015P3MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.259542022-05-10
CVE-2022-22015 [MEDIUM] CVE-2022-22015: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
nvd
CVE-2019-1014P4HIGHCVSS 7.0≥ 6.1.0, < publication2019-06-12
CVE-2019-1014 [HIGH] CVE-2019-1014: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vul
nvd
CVE-2019-0960P4HIGHCVSS 7.0≥ 6.1.0, < publication2019-06-12
CVE-2019-0960 [HIGH] CVE-2019-0960: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vul
nvd
CVE-2019-1017P4HIGHCVSS 7.0≥ 6.1.0, < publication2019-06-12
CVE-2019-1017 [HIGH] CVE-2019-1017: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vul
nvd
CVE-2022-23298P4HIGHCVSS 7.0≥ 6.1.0, < 6.1.7601.258982022-03-09
CVE-2022-23298 [HIGH] CVE-2022-23298: Windows NT OS Kernel Elevation of Privilege Vulnerability
Windows NT OS Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-38033P3MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.261742022-10-11
CVE-2022-38033 [MEDIUM] CVE-2022-38033: Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability
Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability
nvd