Msrc Windows 8.1 For X64-Based Systems vulnerabilities
157 known vulnerabilities affecting msrc/windows_8.1_for_x64-based_systems.
Total CVEs
157
CISA KEV
3
actively exploited
Public exploits
23
Exploited in wild
4
Severity breakdown
CRITICAL6HIGH69MEDIUM72LOW10
Vulnerabilities
Page 5 of 8
CVE-2017-8465HIGHCVSS 7.02017-06-13
CVE-2017-8465 [HIGH] Win32k Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnera
msrc
CVE-2017-8466HIGHCVSS 7.02017-06-13
CVE-2017-8466 [HIGH] Win32k Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnera
msrc
CVE-2017-0193HIGHCVSS 7.82017-06-13
CVE-2017-0193 [HIGH] Hypervisor Code Integrity Elevation of Privilege Vulnerability
Hypervisor Code Integrity Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when Windows Hyper-V instruction emulation fails to properly enforce privilege levels. An attacker who successfully exploited this vulnerability could gain elevated privileges on a target guest operating system. The host operating system is not vulnerable to this attack.
This vulnerability b
msrc
CVE-2017-8468HIGHCVSS 7.02017-06-13
CVE-2017-8468 [HIGH] Win32k Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnera
msrc
CVE-2017-8493MEDIUMCVSS 5.62017-06-13
CVE-2017-8493 [MEDIUM] Windows Security Feature Bypass Vulnerability
Windows Security Feature Bypass Vulnerability
Description: A security feature bypass vulnerability exists when Microsoft Windows fails to enforce case sensitivity for certain variable checks, which could allow an attacker to set variables that are either read-only or require authentication.
To exploit this vulnerability, an attacker could run a specially crafted application to bypass Unified Extensible Firmware Interface (UEFI
msrc
CVE-2017-8553MEDIUMCVSS 4.72017-06-13
CVE-2017-8553 [MEDIUM] Windows Kernel Information Disclosure Vulnerability
Windows Kernel Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
An authenticated attacker could exploit this vulnerability by running a specially crafted application.
The update addresses th
msrc
CVE-2017-8469MEDIUMCVSS 4.7PoC2017-06-13
CVE-2017-8469 [MEDIUM] Windows Kernel Information Disclosure Vulnerability
Windows Kernel Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.
To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
The update addresses t
msrc
CVE-2017-8488MEDIUMCVSS 4.7PoC2017-06-13
CVE-2017-8488 [MEDIUM] Windows Kernel Information Disclosure Vulnerability
Windows Kernel Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.
To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
The update addresses t
msrc
CVE-2017-8474MEDIUMCVSS 4.72017-06-13
CVE-2017-8474 [MEDIUM] Windows Kernel Information Disclosure Vulnerability
Windows Kernel Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.
To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
The update addresses t
msrc
CVE-2017-0291LOWCVSS 3.62017-06-13
CVE-2017-0291 [HIGH] Windows PDF Remote Code Execution
Windows PDF Remote Code Execution
Description: A remote code execution vulnerability exists in Microsoft Windows if a user opens a specially crafted .pdf file. An attacker who successfully exploited the vulnerabilities could cause arbitrary code to execute in the context of the current user.
If a user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs;
msrc
CVE-2017-8460LOWCVSS 3.32017-06-13
CVE-2017-8460 [HIGH] Windows PDF Information Disclosure Vulnerability
Windows PDF Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists in Microsoft Windows when a user opens a specially crafted PDF file. An attacker who successfully exploited the vulnerability could read memory in the context of the current user.
To exploit the vulnerability, an attacker would have to trick the user into opening the PDF file.
The update addresses the vulnerability by
msrc
CVE-2017-0259MEDIUMCVSS 4.7PoC2017-05-09
CVE-2017-0259 [MEDIUM] Windows Kernel Information Disclosure Vulnerability
Windows Kernel Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.
To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
The update addresses t
msrc
CVE-2017-0169HIGHCVSS 7.32017-04-11
CVE-2017-0169 [MEDIUM] Windows Hyper-V Information Disclosure Vulnerability
Windows Hyper-V Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker on a guest operating system could run a specially crafted application that could cause the Hyper-V host operating system to disclos
msrc
CVE-2017-0162HIGHCVSS 7.62017-04-11
CVE-2017-0162 [HIGH] Hyper-V Remote Code Execution Vulnerability
Hyper-V Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary code.
msrc
CVE-2017-0163HIGHCVSS 7.62017-04-11
CVE-2017-0163 [HIGH] Hyper-V Remote Code Execution Vulnerability
Hyper-V Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary code.
msrc
CVE-2017-0168HIGHCVSS 7.72017-04-11
CVE-2017-0168 [MEDIUM] Hyper-V Information Disclosure Vulnerability
Hyper-V Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host operating system fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker on a guest operating system could run a specially crafted application that could cause the Hyper-V host operating system to disc
msrc
CVE-2017-0180HIGHCVSS 7.62017-04-11
CVE-2017-0180 [HIGH] Hyper-V Remote Code Execution Vulnerability
Hyper-V Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary code.
msrc
CVE-2017-0185MEDIUMCVSS 5.82017-04-11
CVE-2017-0185 [MEDIUM] Windows Hyper-V Denial of Service Vulnerability
Windows Hyper-V Denial of Service Vulnerability
Description: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash.
To exploit the vulnerability, an attacker who already has a privileged account on a guest o
msrc
CVE-2017-0183MEDIUMCVSS 5.82017-04-11
CVE-2017-0183 [MEDIUM] Windows Hyper-V Denial of Service Vulnerability
Windows Hyper-V Denial of Service Vulnerability
Description: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash.
To exploit the vulnerability, an attacker who already has a privileged account on a guest o
msrc
CVE-2017-0211MEDIUMCVSS 5.0PoC2017-04-11
CVE-2017-0211 [MEDIUM] Windows OLE Elevation of Privilege Vulnerability
Windows OLE Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in Microsoft Windows OLE when it fails an integrity-level check.
An attacker who successfully exploited the vulnerability could allow an application with limited privileges on an affected system to execute code at a medium integrity level. The vulnerability by itself does not allow arbitrary code to be run, but can b
msrc