Msrc Windows 8.1 For X64-Based Systems vulnerabilities

157 known vulnerabilities affecting msrc/windows_8.1_for_x64-based_systems.

Total CVEs
157
CISA KEV
3
actively exploited
Public exploits
23
Exploited in wild
4
Severity breakdown
CRITICAL6HIGH69MEDIUM72LOW10

Vulnerabilities

Page 8 of 8
CVE-2016-3300MEDIUMCVSS 6.82016-08-09
CVE-2016-3300 [HIGH] NetLogon Elevation of Privilege Vulnerability NetLogon Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when Windows Netlogon improperly establishes a secure communications channel to a domain controller. An attacker who successfully exploited the vulnerability could run a specially crafted application on a domain-joined system. To exploit the vulnerability, an attacker would require access to a domain-joined machine that poin
msrc
CVE-2016-3258MEDIUMCVSS 6.32016-07-12
CVE-2016-3258 [MEDIUM] Windows File System Security Feature Bypass Vulnerability Windows File System Security Feature Bypass Vulnerability Description: A security feature bypass vulnerability exists in the Windows kernel that could allow an attacker to exploit time of check time of use (TOCTOU) issues in file path-based checks from a low-integrity application. An attacker who successfully exploited this vulnerability could potentially modify files outside of a low-integrity level application. T
msrc
CVE-2016-3287MEDIUMCVSS 6.22016-07-12
CVE-2016-3287 [MEDIUM] Secure Boot Security Feature Bypass Vulnerability Secure Boot Security Feature Bypass Vulnerability Description: A security feature bypass vulnerability exists when Windows Secure Boot improperly applies an affected policy. An attacker who successfully exploited this vulnerability could disable code integrity checks, allowing test-signed executables and drivers to be loaded on a target device. In addition, an attacker could bypass the Secure Boot Integrity Validation for
msrc
CVE-2016-3272LOWCVSS 3.12016-07-12
CVE-2016-3272 [LOW] Windows Kernel Information Disclosure Vulnerability Windows Kernel Information Disclosure Vulnerability Description: An information disclosure vulnerability exists in Microsoft Windows when the Windows kernel fails to properly handle certain page fault system calls. An authenticated attacker who successfully exploited this vulnerability could disclose information from one process to another. To exploit the vulnerability, an attacker would have to either log on locally to an
msrc
CVE-2016-3203CRITICALCVSS 6.52016-06-14
CVE-2016-3203 [MEDIUM] Windows PDF Remote Code Execution Windows PDF Remote Code Execution Description: A remote code execution vulnerability exists in Microsoft Windows if a user opens a specially crafted .pdf file. An attacker who successfully exploited the vulnerabilities could cause arbitrary code to execute in the context of the current user. If a user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install program
msrc
CVE-2016-3201HIGHCVSS 6.52016-06-14
CVE-2016-3201 [MEDIUM] Windows PDF Information Disclosure Vulnerability Windows PDF Information Disclosure Vulnerability Description: An information disclosure vulnerability exists in Microsoft Windows when a user opens a specially crafted PDF file. An attacker who successfully exploited the vulnerability could read memory in the context of the current user. To exploit the vulnerability, an attacker would have to trick the user into opening the PDF file. The update addresses the vulnerability b
msrc
CVE-2016-3230HIGHCVSS 5.02016-06-14
CVE-2016-3230 [MEDIUM] Windows Search Denial of Service Vulnerability Windows Search Denial of Service Vulnerability Description: This vulnerability occurs when the Windows Search component fails to properly handle certain objects in memory. An attacker who successfully exploited this vulnerability could cause server performance to degrade sufficiently to cause a denial of service condition. To exploit this vulnerability, an attacker could use it to cause a denial of service attack and disrupt
msrc
CVE-2016-3215HIGHCVSS 6.52016-06-14
CVE-2016-3215 [MEDIUM] Windows PDF Information Disclosure Vulnerability Windows PDF Information Disclosure Vulnerability Description: An information disclosure vulnerability exists in Microsoft Windows when a user opens a specially crafted PDF file. An attacker who successfully exploited the vulnerability could read memory in the context of the current user. To exploit the vulnerability, an attacker would have to trick the user into opening the PDF file. The update addresses the vulnerability b
msrc
CVE-2016-0182CRITICALCVSS 7.82016-05-10
CVE-2016-0182 [HIGH] Windows Journal Memory Corruption Vulnerability Windows Journal Memory Corruption Vulnerability Description: A remote code execution vulnerability exists in Microsoft Windows when a specially crafted Journal file is opened in Windows Journal. An attacker who successfully exploited this vulnerability could cause arbitrary code to execute in the context of the current user. If a user is logged on with administrative user rights, an attacker could take control of the affected
msrc
CVE-2016-0179CRITICALCVSS 7.82016-05-10
CVE-2016-0179 [HIGH] Windows Shell Remote Code Execution Vulnerability Windows Shell Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists when Windows Shell improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code and take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accoun
msrc
CVE-2016-0176HIGHCVSS 7.82016-05-10
CVE-2016-0176 [HIGH] DirectX Elevation of Privilege Vulnerability DirectX Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would first have t
msrc
CVE-2016-0185HIGHCVSS 7.8KEVPoC2016-05-10
CVE-2016-0185 [HIGH] Windows Media Center Remote Code Execution Vulnerability Windows Media Center Remote Code Execution Vulnerability Description: A vulnerability exists in Windows Media Center that could allow remote code execution if Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code. An attacker who successfully exploited this vulnerability could take control of an affected system. Customers whose accounts are configured to have fewer
msrc
CVE-2016-0090HIGHCVSS 7.12016-04-12
CVE-2016-0090 [HIGH] Windows Hyper-V Information Disclosure Vulnerability Windows Hyper-V Information Disclosure Vulnerability Description: An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker on a guest operating system could run a specially crafted application that could cause the Hyper-V host operating system to disclose
msrc
CVE-2016-0151HIGHCVSS 7.8KEVPoC2016-04-12
CVE-2016-0151 [HIGH] Windows CSRSS Security Feature Bypass Vulnerability Windows CSRSS Security Feature Bypass Vulnerability Description: A security feature bypass vulnerability exists in Microsoft Windows when the Client-Server Run-time Subsystem (CSRSS) fails to properly manage process tokens in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator. An attacker could then install programs; view, change, or delete data; or create new acc
msrc
CVE-2016-0153HIGHCVSS 7.82016-04-12
CVE-2016-0153 [HIGH] Windows OLE Remote Code Execution Vulnerability Windows OLE Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input. An attacker could exploit the vulnerability to execute malicious code. To exploit the vulnerability, an attacker would have to convince a user to open either a specially crafted file or a program from either a webpage or an email message. The update addresse
msrc
CVE-2016-0088HIGHCVSS 9.32016-04-12
CVE-2016-0088 [CRITICAL] Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary c
msrc
CVE-2016-0089HIGHCVSS 7.12016-04-12
CVE-2016-0089 [HIGH] Windows Hyper-V Information Disclosure Vulnerability Windows Hyper-V Information Disclosure Vulnerability Description: An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker on a guest operating system could run a specially crafted application that could cause the Hyper-V host operating system to disclose
msrc