Msrc Windows 7 vulnerabilities
1,628 known vulnerabilities affecting msrc/windows_7.
Total CVEs
1,628
CISA KEV
72
actively exploited
Public exploits
162
Exploited in wild
82
Severity breakdown
CRITICAL24HIGH1098MEDIUM487LOW19
Vulnerabilities
Page 32 of 82
CVE-2020-16997HIGHCVSS 7.72020-11-10
CVE-2020-16997 [HIGH] Remote Desktop Protocol Server Information Disclosure Vulnerability
Remote Desktop Protocol Server Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is unauthorized read access to Windows RDP server process.
Microsoft Windows: Microsoft Windows
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Infor
msrc
CVE-2020-17014HIGHCVSS 7.82020-11-10
CVE-2020-17014 [HIGH] Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
Microsoft Windows: Microsoft Windows
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4586786
msrc
CVE-2020-17029MEDIUMCVSS 5.52020-11-10
CVE-2020-17029 [MEDIUM] Windows Canonical Display Driver Information Disclosure Vulnerability
Windows Canonical Display Driver Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is memory layout - the vulnerability allows an attacker to collect information that facilitates predicting addressing of the memory.
Microsoft Graphics Compo
msrc
CVE-2020-17004MEDIUMCVSS 5.52020-11-10
CVE-2020-17004 [MEDIUM] Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is the contents of Kernel memory. An attacker could read the contents of Kernel memory from a user mode process.
Microsoft Graphics Component: Microsoft Graphics Compone
msrc
CVE-2020-1599MEDIUMCVSS 5.52020-11-10
CVE-2020-1599 [MEDIUM] Windows Spoofing Vulnerability
Windows Spoofing Vulnerability
Microsoft Windows: Microsoft Windows
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4586785
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx
msrc
CVE-2020-17045MEDIUMCVSS 5.52020-11-10
CVE-2020-17045 [MEDIUM] Windows KernelStream Information Disclosure Vulnerability
Windows KernelStream Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is memory layout - the vulnerability allows an attacker to collect information that facilitates predicting addressing of the memory.
Microsoft Windows: Microsoft Windows
Microsoft:
msrc
CVE-2020-17069MEDIUMCVSS 5.52020-11-10
CVE-2020-17069 [MEDIUM] Windows NDIS Information Disclosure Vulnerability
Windows NDIS Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is memory layout - the vulnerability allows an attacker to collect information that facilitates predicting addressing of the memory.
Windows NDIS: Windows NDIS
Microsoft: Microsoft
Customer Actio
msrc
CVE-2020-17036MEDIUMCVSS 5.52020-11-10
CVE-2020-17036 [MEDIUM] Windows Function Discovery SSDP Provider Information Disclosure Vulnerability
Windows Function Discovery SSDP Provider Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is memory layout - the vulnerability allows an attacker to collect information that facilitates predicting addressing of the memory.
Microsof
msrc
CVE-2020-17000MEDIUMCVSS 5.52020-11-10
CVE-2020-17000 [MEDIUM] Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory.
Microsoft Windows: Microsoft Windows
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Information Disclosure
Exploit Statu
msrc
CVE-2020-16936HIGHCVSS 7.82020-10-13
CVE-2020-16936 [HIGH] Windows Backup Service Elevation of Privilege Vulnerability
Windows Backup Service Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability
msrc
CVE-2020-16974HIGHCVSS 7.82020-10-13
CVE-2020-16974 [HIGH] Windows Backup Service Elevation of Privilege Vulnerability
Windows Backup Service Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability
msrc
CVE-2020-16920HIGHCVSS 7.82020-10-13
CVE-2020-16920 [HIGH] Windows Application Compatibility Client Library Elevation of Privilege Vulnerability
Windows Application Compatibility Client Library Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when the Windows Application Compatibility Client Library improperly handles registry operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.
To exploit the vulnerability, an attacker would first nee
msrc
CVE-2020-16912HIGHCVSS 7.82020-10-13
CVE-2020-16912 [HIGH] Windows Backup Service Elevation of Privilege Vulnerability
Windows Backup Service Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability
msrc
CVE-2020-16902HIGHCVSS 7.82020-10-13
CVE-2020-16902 [HIGH] Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.
A locally authenticated attacker could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create n
msrc
CVE-2020-16975HIGHCVSS 7.82020-10-13
CVE-2020-16975 [HIGH] Windows Backup Service Elevation of Privilege Vulnerability
Windows Backup Service Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability
msrc
CVE-2020-16972HIGHCVSS 7.82020-10-13
CVE-2020-16972 [HIGH] Windows Backup Service Elevation of Privilege Vulnerability
Windows Backup Service Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability
msrc
CVE-2020-16923HIGHCVSS 7.82020-10-13
CVE-2020-16923 [HIGH] Microsoft Graphics Components Remote Code Execution Vulnerability
Microsoft Graphics Components Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system.
To exploit the vulnerability, a user would have to open a specially crafted file.
The security update address
msrc
CVE-2020-16973HIGHCVSS 7.82020-10-13
CVE-2020-16973 [HIGH] Windows Backup Service Elevation of Privilege Vulnerability
Windows Backup Service Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability
msrc
CVE-2020-16900HIGHCVSS 7.02020-10-13
CVE-2020-16900 [HIGH] Windows Event System Elevation of Privilege Vulnerability
Windows Event System Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when the Windows Event System improperly handles objects in memory.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability by
msrc
CVE-2020-16939HIGHCVSS 7.82020-10-13
CVE-2020-16939 [HIGH] Group Policy Elevation of Privilege Vulnerability
Group Policy Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when Group Policy improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted application to take control over the affected system.
msrc