cbcvebase.

Microsoft Windows 7 Service Pack 1 vulnerabilities

817 known vulnerabilities affecting microsoft/windows_7_service_pack_1.

Total CVEs
817
CISA KEV
28
actively exploited
Public exploits
34
Exploited in wild
40
Severity breakdown
CRITICAL25HIGH615MEDIUM176LOW1

Vulnerabilities

Page 31 of 41
CVE-2022-41097P3MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.262212022-11-09
CVE-2022-41097 [MEDIUM] CVE-2022-41097: Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability
nvd
CVE-2019-0723P4MEDIUMCVSS 5.8≥ 6.1.0, < publication2019-08-14
CVE-2019-0723 [MEDIUM] CWE-20 CVE-2019-0723: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. To exploit the vulnerability, an attacker who already has a privileged account
nvd
CVE-2019-0715P4MEDIUMCVSS 5.8≥ 6.1.0, < publication2019-08-14
CVE-2019-0715 [MEDIUM] CWE-20 CVE-2019-0715: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. To exploit the vulnerability, an attacker who already has a privileged account
nvd
CVE-2019-0714P4MEDIUMCVSS 5.8≥ 6.1.0, < publication2019-08-14
CVE-2019-0714 [MEDIUM] CWE-20 CVE-2019-0714: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. To exploit the vulnerability, an attacker who already has a privileged account
nvd
CVE-2021-41332P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.257402021-10-13
CVE-2021-41332 [MEDIUM] CVE-2021-41332: Windows Print Spooler Information Disclosure Vulnerability Windows Print Spooler Information Disclosure Vulnerability
nvd
CVE-2021-38629P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.257122021-09-15
CVE-2021-38629 [MEDIUM] CVE-2021-38629: Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
nvd
CVE-2022-21862P4HIGHCVSS 7.0≥ 6.1.0, < 6.1.7601.258292022-01-11
CVE-2022-21862 [HIGH] CVE-2022-21862: Windows Application Model Core API Elevation of Privilege Vulnerability Windows Application Model Core API Elevation of Privilege Vulnerability
nvd
CVE-2022-30151P4HIGHCVSS 7.0≥ 6.1.0, < 6.1.7601.259842022-06-15
CVE-2022-30151 [HIGH] CVE-2022-30151: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd
CVE-2022-26827P4HIGHCVSS 7.0≥ 6.1.0, < 6.1.7601.259242022-04-15
CVE-2022-26827 [HIGH] CWE-362 CVE-2022-26827: Windows File Server Resource Management Service Elevation of Privilege Vulnerability Windows File Server Resource Management Service Elevation of Privilege Vulnerability
nvd
CVE-2022-22042P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.260222022-07-12
CVE-2022-22042 [MEDIUM] CVE-2022-22042: Windows Hyper-V Information Disclosure Vulnerability Windows Hyper-V Information Disclosure Vulnerability
nvd
CVE-2022-24498P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.259242022-04-15
CVE-2022-24498 [MEDIUM] CVE-2022-24498: Windows iSCSI Target Service Information Disclosure Vulnerability Windows iSCSI Target Service Information Disclosure Vulnerability
nvd
CVE-2019-0984P4HIGHCVSS 7.0≥ 6.1.0, < publication2019-06-12
CVE-2019-0984 [HIGH] CVE-2019-0984: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted appli
nvd
CVE-2022-22717P4HIGHCVSS 7.0≥ 6.1.0, < 6.1.7601.258602022-02-09
CVE-2022-22717 [HIGH] CVE-2022-22717: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-21859P4HIGHCVSS 7.0≥ 6.1.0, < 6.1.7601.258292022-01-11
CVE-2022-21859 [HIGH] CVE-2022-21859: Windows Accounts Control Elevation of Privilege Vulnerability Windows Accounts Control Elevation of Privilege Vulnerability
nvd
CVE-2022-22036P4HIGHCVSS 7.0≥ 6.1.0, < 6.1.7601.260222022-07-12
CVE-2022-22036 [HIGH] CVE-2022-22036: Performance Counters for Windows Elevation of Privilege Vulnerability Performance Counters for Windows Elevation of Privilege Vulnerability
nvd
CVE-2022-30224P4HIGHCVSS 7.0≥ 6.1.0, < 6.1.7601.260222022-07-12
CVE-2022-30224 [HIGH] CVE-2022-30224: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
nvd
CVE-2019-0986P4MEDIUMCVSS 6.3≥ 6.1.0, < publication2019-06-12
CVE-2019-0986 [MEDIUM] CWE-59 CVE-2019-0986: An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) impro An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a spe
nvd
CVE-2022-21925P4MEDIUMCVSS 5.3≥ 6.1.0, < 6.1.7601.258292022-01-11
CVE-2022-21925 [MEDIUM] CVE-2022-21925: Windows BackupKey Remote Protocol Security Feature Bypass Vulnerability Windows BackupKey Remote Protocol Security Feature Bypass Vulnerability
nvd
CVE-2022-29112P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.259542022-05-10
CVE-2022-29112 [MEDIUM] CVE-2022-29112: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2021-31186P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.24597≥ 6.1.0, < 6.1.7601.245982021-05-11
CVE-2021-31186 [MEDIUM] CVE-2021-31186: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
nvd
Microsoft Windows 7 Service Pack 1 vulnerabilities | cvebase