Microsoft Windows 7 Service Pack 1 vulnerabilities
817 known vulnerabilities affecting microsoft/windows_7_service_pack_1.
Total CVEs
817
CISA KEV
28
actively exploited
Public exploits
34
Exploited in wild
40
Severity breakdown
CRITICAL25HIGH615MEDIUM176LOW1
Vulnerabilities
Page 33 of 41
CVE-2022-37977P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.261742022-10-11
CVE-2022-37977 [MEDIUM] CVE-2022-37977: Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
nvd
CVE-2023-21560P4MEDIUMCVSS 6.6≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21560 [MEDIUM] CWE-122 CVE-2023-21560: Windows Boot Manager Security Feature Bypass Vulnerability
Windows Boot Manager Security Feature Bypass Vulnerability
nvd
CVE-2019-0716P4MEDIUMCVSS 5.8≥ 6.1.0, < publication2019-08-14
CVE-2019-0716 [MEDIUM] CVE-2019-0716: A denial of service vulnerability exists when Windows improperly handles objects in memory. An attac
A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an
nvd
CVE-2022-35759P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.260652023-05-31
CVE-2022-35759 [MEDIUM] CVE-2022-35759: Windows Local Security Authority (LSA) Denial of Service Vulnerability
Windows Local Security Authority (LSA) Denial of Service Vulnerability
nvd
CVE-2022-38032P4MEDIUMCVSS 6.6≥ 6.1.0, < 6.1.7601.261742022-10-11
CVE-2022-38032 [MEDIUM] CVE-2022-38032: Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability
Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability
nvd
CVE-2022-22023P4MEDIUMCVSS 6.6≥ 6.1.0, < 6.1.7601.260222022-07-12
CVE-2022-22023 [MEDIUM] CVE-2022-22023: Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability
Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability
nvd
CVE-2019-0968P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2019-06-12
CVE-2019-0968 [MEDIUM] CVE-2019-0968: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a spe
nvd
CVE-2019-1013P4MEDIUMCVSS 4.7≥ 6.1.0, < publication2019-06-12
CVE-2019-1013 [MEDIUM] CWE-200 CVE-2019-1013: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2019-1053P4MEDIUMCVSS 6.3≥ 6.1.0, < publication2019-06-12
CVE-2019-1053 [MEDIUM] CWE-59 CVE-2019-1053: An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder short
An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the vulnerability could elevate privileges by escaping a sandbox.
To exploit this vulnerability, an attacker would require unprivileged execution on the victim system.
The security update addresses the vulnera
nvd
CVE-2020-16914P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2020-10-16
CVE-2020-16914 [MEDIUM] CVE-2020-16914: <p>An information disclosure vulnerability exists in the way that the Windows Graphics Device Interf
An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface Plus (GDI+) handles objects in memory, allowing an attacker to retrieve information from a targeted system. By itself, the information disclosure does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses i
nvd
CVE-2021-43224P4MEDIUMCVSS 5.5≥ 6.1.0, < 6.1.7601.257962021-12-15
CVE-2021-43224 [MEDIUM] CVE-2021-43224: Windows Common Log File System Driver Information Disclosure Vulnerability
Windows Common Log File System Driver Information Disclosure Vulnerability
nvd
CVE-2019-1187P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2019-08-14
CVE-2019-1187 [MEDIUM] CWE-611 CVE-2019-1187: A denial of service vulnerability exists when the XmlLite runtime (XmlLite.dll) improperly parses XM
A denial of service vulnerability exists when the XmlLite runtime (XmlLite.dll) improperly parses XML input. An attacker who successfully exploited this vulnerability could cause a denial of service against an XML application.
A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to an XML application
nvd
CVE-2022-41086P4MEDIUMCVSS 6.4≥ 6.1.0, < 6.1.7601.262212022-11-09
CVE-2022-41086 [MEDIUM] CWE-362 CVE-2022-41086: Windows Group Policy Elevation of Privilege Vulnerability
Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2022-24503P4MEDIUMCVSS 5.3≥ 6.1.0, < 6.1.7601.258982022-03-09
CVE-2022-24503 [MEDIUM] CVE-2022-24503: Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability
nvd
CVE-2019-1228P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2019-08-14
CVE-2019-1228 [MEDIUM] CWE-200 CVE-2019-1228: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted applic
nvd
CVE-2020-1383P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2020-08-17
CVE-2020-1383 [MEDIUM] CVE-2020-1383: An information disclosure vulnerability exists in RPC if the server has Routing and Remote Access en
An information disclosure vulnerability exists in RPC if the server has Routing and Remote Access enabled. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system
To exploit this vulnerability, an attacker would need to run a specially crafted application against an RPC server which has Routin
nvd
CVE-2020-16922P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2020-10-16
CVE-2020-16922 [MEDIUM] CWE-347 CVE-2020-16922: <p>A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker w
A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files.
In an attack scenario, an attacker could bypass security features intended to prevent improperly signed files from being loaded.
The update addr
nvd
CVE-2021-24080P4MEDIUMCVSS 6.5≥ 6.1.0, < publication2021-02-25
CVE-2021-24080 [MEDIUM] CVE-2021-24080: Windows Trust Verification API Denial of Service Vulnerability
Windows Trust Verification API Denial of Service Vulnerability
nvd
CVE-2022-35747P4MEDIUMCVSS 5.9≥ 6.1.0, < 6.1.7601.260652023-05-31
CVE-2022-35747 [MEDIUM] CVE-2022-35747: Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
nvd
CVE-2019-1143P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2019-08-14
CVE-2019-1143 [MEDIUM] CWE-200 CVE-2019-1143: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open
nvd