Microsoft Windows 7 Service Pack 1 vulnerabilities
817 known vulnerabilities affecting microsoft/windows_7_service_pack_1.
Total CVEs
817
CISA KEV
28
actively exploited
Public exploits
34
Exploited in wild
40
Severity breakdown
CRITICAL25HIGH615MEDIUM176LOW1
Vulnerabilities
Page 34 of 41
CVE-2019-1154P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2019-08-14
CVE-2019-1154 [MEDIUM] CWE-200 CVE-2019-1154: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open
nvd
CVE-2019-1158P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2019-08-14
CVE-2019-1158 [MEDIUM] CWE-200 CVE-2019-1158: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open
nvd
CVE-2021-31188P4MEDIUMCVSS 5.5≥ 6.1.0, < 6.1.7601.24597≥ 6.1.0, < 6.1.7601.245982021-05-11
CVE-2021-31188 [MEDIUM] CWE-416 CVE-2021-31188: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2020-16889P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2020-10-16
CVE-2020-16889 [MEDIUM] CVE-2020-16889: <p>An information disclosure vulnerability exists when the Windows KernelStream improperly handles o
An information disclosure vulnerability exists when the Windows KernelStream improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted applic
nvd
CVE-2020-1589P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2020-09-11
CVE-2020-1589 [MEDIUM] CVE-2020-1589: <p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. T
nvd
CVE-2020-16897P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2020-10-16
CVE-2020-16897 [MEDIUM] CVE-2020-16897: <p>An information disclosure vulnerability exists when NetBIOS over TCP (NBT) Extensions (NetBT) imp
An information disclosure vulnerability exists when NetBIOS over TCP (NBT) Extensions (NetBT) improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have run a specially crafted application. The vulnerabi
nvd
CVE-2022-34728P4MEDIUMCVSS 5.5≥ 6.1.0, < 6.1.7601.261152022-09-13
CVE-2022-34728 [MEDIUM] CVE-2022-34728: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2022-26935P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.1.7601.259542022-05-10
CVE-2022-26935 [MEDIUM] CVE-2022-26935: Windows WLAN AutoConfig Service Information Disclosure Vulnerability
Windows WLAN AutoConfig Service Information Disclosure Vulnerability
nvd
CVE-2021-1656P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2021-01-12
CVE-2021-1656 [MEDIUM] CVE-2021-1656: TPM Device Driver Information Disclosure Vulnerability
TPM Device Driver Information Disclosure Vulnerability
nvd
CVE-2019-1078P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2019-08-14
CVE-2019-1078 [MEDIUM] CWE-200 CVE-2019-1078: An information disclosure vulnerability exists when the Windows Graphics component improperly handle
An information disclosure vulnerability exists when the Windows Graphics component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
An authenticated attacker could exploit this vulnerability by running a specially crafted application.
The u
nvd
CVE-2020-1474P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2020-08-17
CVE-2020-1474 [MEDIUM] CVE-2020-1474: An information disclosure vulnerability exists when the Windows Image Acquisition (WIA) Service impr
An information disclosure vulnerability exists when the Windows Image Acquisition (WIA) Service improperly discloses contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit the vulnerability, an authenticated attacker could connect an imaging device (camera,
nvd
CVE-2022-21899P4MEDIUMCVSS 5.5≥ 6.1.0, < 6.1.7601.258292022-01-11
CVE-2022-21899 [MEDIUM] CVE-2022-21899: Windows Extensible Firmware Interface Security Feature Bypass Vulnerability
Windows Extensible Firmware Interface Security Feature Bypass Vulnerability
nvd
CVE-2019-1039P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2019-06-12
CVE-2019-1039 [MEDIUM] CWE-665 CVE-2019-1039: An information disclosure vulnerability exists when the Windows kernel improperly initializes object
An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.
To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
The update addre
nvd
CVE-2023-21682P4MEDIUMCVSS 5.3≥ 6.1.0, < 6.1.7601.263212023-01-10
CVE-2023-21682 [MEDIUM] CWE-125 CVE-2023-21682: Windows Point-to-Point Protocol (PPP) Information Disclosure Vulnerability
Windows Point-to-Point Protocol (PPP) Information Disclosure Vulnerability
nvd
CVE-2021-1696P4MEDIUMCVSS 5.5≥ 6.1.0, < publication2021-01-12
CVE-2021-1696 [MEDIUM] CVE-2021-1696: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2019-1010P4MEDIUMCVSS 4.7≥ 6.1.0, < publication2019-06-12
CVE-2019-1010 [MEDIUM] CWE-200 CVE-2019-1010: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2019-0977P4MEDIUMCVSS 4.7≥ 6.1.0, < publication2019-06-12
CVE-2019-0977 [MEDIUM] CWE-200 CVE-2019-0977: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2019-1048P4MEDIUMCVSS 4.7≥ 6.1.0, < publication2019-06-12
CVE-2019-1048 [MEDIUM] CWE-200 CVE-2019-1048: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2019-1015P4MEDIUMCVSS 4.7≥ 6.1.0, < publication2019-06-12
CVE-2019-1015 [MEDIUM] CWE-200 CVE-2019-1015: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2019-1011P4MEDIUMCVSS 4.7≥ 6.1.0, < publication2019-06-12
CVE-2019-1011 [MEDIUM] CWE-200 CVE-2019-1011: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd