Microsoft Windows 7 Service Pack 1 vulnerabilities
817 known vulnerabilities affecting microsoft/windows_7_service_pack_1.
Total CVEs
817
CISA KEV
28
actively exploited
Public exploits
34
Exploited in wild
40
Severity breakdown
CRITICAL25HIGH615MEDIUM176LOW1
Vulnerabilities
Page 31 of 41
CVE-2022-41097P3MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.262212022-11-09
CVE-2022-41097 [MEDIUM] CVE-2022-41097: Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability
Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability
nvd
CVE-2019-0723P4MEDIUMCVSS 5.8≥ 6.1.0, < publication2019-08-14
CVE-2019-0723 [MEDIUM] CWE-20 CVE-2019-0723: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash.
To exploit the vulnerability, an attacker who already has a privileged account
nvd
CVE-2019-0715P4MEDIUMCVSS 5.8≥ 6.1.0, < publication2019-08-14
CVE-2019-0715 [MEDIUM] CWE-20 CVE-2019-0715: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash.
To exploit the vulnerability, an attacker who already has a privileged account
nvd
CVE-2019-0714P4MEDIUMCVSS 5.8≥ 6.1.0, < publication2019-08-14
CVE-2019-0714 [MEDIUM] CWE-20 CVE-2019-0714: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash.
To exploit the vulnerability, an attacker who already has a privileged account
nvd
CVE-2021-41332P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.257402021-10-13
CVE-2021-41332 [MEDIUM] CVE-2021-41332: Windows Print Spooler Information Disclosure Vulnerability
Windows Print Spooler Information Disclosure Vulnerability
nvd
CVE-2021-38629P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.257122021-09-15
CVE-2021-38629 [MEDIUM] CVE-2021-38629: Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
nvd
CVE-2022-21862P4HIGHCVSS 7.0≥ 6.1.0, < 6.1.7601.258292022-01-11
CVE-2022-21862 [HIGH] CVE-2022-21862: Windows Application Model Core API Elevation of Privilege Vulnerability
Windows Application Model Core API Elevation of Privilege Vulnerability
nvd
CVE-2022-30151P4HIGHCVSS 7.0≥ 6.1.0, < 6.1.7601.259842022-06-15
CVE-2022-30151 [HIGH] CVE-2022-30151: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd
CVE-2022-26827P4HIGHCVSS 7.0≥ 6.1.0, < 6.1.7601.259242022-04-15
CVE-2022-26827 [HIGH] CWE-362 CVE-2022-26827: Windows File Server Resource Management Service Elevation of Privilege Vulnerability
Windows File Server Resource Management Service Elevation of Privilege Vulnerability
nvd
CVE-2022-22042P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.260222022-07-12
CVE-2022-22042 [MEDIUM] CVE-2022-22042: Windows Hyper-V Information Disclosure Vulnerability
Windows Hyper-V Information Disclosure Vulnerability
nvd
CVE-2022-24498P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.259242022-04-15
CVE-2022-24498 [MEDIUM] CVE-2022-24498: Windows iSCSI Target Service Information Disclosure Vulnerability
Windows iSCSI Target Service Information Disclosure Vulnerability
nvd
CVE-2019-0984P4HIGHCVSS 7.0≥ 6.1.0, < publication2019-06-12
CVE-2019-0984 [HIGH] CVE-2019-0984: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted appli
nvd
CVE-2022-22717P4HIGHCVSS 7.0≥ 6.1.0, < 6.1.7601.258602022-02-09
CVE-2022-22717 [HIGH] CVE-2022-22717: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-21859P4HIGHCVSS 7.0≥ 6.1.0, < 6.1.7601.258292022-01-11
CVE-2022-21859 [HIGH] CVE-2022-21859: Windows Accounts Control Elevation of Privilege Vulnerability
Windows Accounts Control Elevation of Privilege Vulnerability
nvd
CVE-2022-22036P4HIGHCVSS 7.0≥ 6.1.0, < 6.1.7601.260222022-07-12
CVE-2022-22036 [HIGH] CVE-2022-22036: Performance Counters for Windows Elevation of Privilege Vulnerability
Performance Counters for Windows Elevation of Privilege Vulnerability
nvd
CVE-2022-30224P4HIGHCVSS 7.0≥ 6.1.0, < 6.1.7601.260222022-07-12
CVE-2022-30224 [HIGH] CVE-2022-30224: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
nvd
CVE-2019-0986P4MEDIUMCVSS 6.3≥ 6.1.0, < publication2019-06-12
CVE-2019-0986 [MEDIUM] CWE-59 CVE-2019-0986: An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) impro
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a spe
nvd
CVE-2022-21925P4MEDIUMCVSS 5.3≥ 6.1.0, < 6.1.7601.258292022-01-11
CVE-2022-21925 [MEDIUM] CVE-2022-21925: Windows BackupKey Remote Protocol Security Feature Bypass Vulnerability
Windows BackupKey Remote Protocol Security Feature Bypass Vulnerability
nvd
CVE-2022-29112P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.259542022-05-10
CVE-2022-29112 [MEDIUM] CVE-2022-29112: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2021-31186P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.24597≥ 6.1.0, < 6.1.7601.245982021-05-11
CVE-2021-31186 [MEDIUM] CVE-2021-31186: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
nvd