target entity

Windows

170 source-linked records in the current knowledge graph.

high

CVE-2008-4250: Microsoft Windows Buffer Overflow Vulnerability

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2008-4250EPSS 98.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2026-32202: Microsoft Windows Protection Mechanism Failure Vulnerability

Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-32202EPSS 64.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-60710: Microsoft Windows Link Following Vulnerability

Microsoft Windows contains a link following vulnerability that allows for privilege escalation Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-60710EPSS 4.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2023-36424: Microsoft Windows Out-of-Bounds Read Vulnerability

Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2023-36424EPSS 12.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2008-0015: Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability

Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2008-0015EPSS 76.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2026-21513: Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability

Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-21513EPSS 15.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2026-21525: Microsoft Windows NULL Pointer Dereference Vulnerability

Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-21525EPSS 5.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2026-21510: Microsoft Windows Shell Protection Mechanism Failure Vulnerability

Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-21510EPSS 25.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2026-21533: Microsoft Windows Improper Privilege Management Vulnerability

Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-21533EPSS 3.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2026-21519: Microsoft Windows Type Confusion Vulnerability

Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-21519EPSS 2.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2026-20805: Microsoft Windows Information Disclosure Vulnerability

Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-20805EPSS 5.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-62221: Microsoft Windows Use After Free Vulnerability

Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-62221EPSS 2.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-62215: Microsoft Windows Race Condition Vulnerability

Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could enable the attacker to gain SYSTEM-level access. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-62215EPSS 6.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-59287: Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability

Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-59287EPSS 100.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-33073: Microsoft Windows SMB Client Improper Access Control Vulnerability

Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-33073EPSS 65.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24990: Microsoft Windows Untrusted Pointer Dereference Vulnerability

Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully exploited this vulnerability could gain administrator privileges. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24990EPSS 6.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-59230: Microsoft Windows Improper Access Control Vulnerability

Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-59230EPSS 2.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2021-43226: Microsoft Windows Privilege Escalation Vulnerability

Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2021-43226EPSS 3.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2013-3918: Microsoft Windows Out-of-Bounds Write Vulnerability

Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a specially crafted webpage. When a user views the webpage, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2013-3918EPSS 73.9%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2011-3402: Microsoft Windows Remote Code Execution Vulnerability

Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2011-3402EPSS 78.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2025-33053: Microsoft Windows External Control of File Name or Path Vulnerability

Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execute code from a remote WebDAV location specified by the WorkingDirectory attribute of Internet Shortcut files. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-33053EPSS 81.6%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-32709: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to escalate privileges to administrator. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-32709EPSS 1.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-30397: Microsoft Windows Scripting Engine Type Confusion Vulnerability

Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthorized attacker to execute code over a network via a specially crafted URL. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-30397EPSS 21.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-32706: Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability

Microsoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overflow vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-32706EPSS 2.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-32701: Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability

Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-32701EPSS 1.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-30400: Microsoft Windows DWM Core Library Use-After-Free Vulnerability

Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-30400EPSS 1.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24054: Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability

Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24054EPSS 59.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-29824: Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability

Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-29824EPSS 13.5%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24993: Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability

Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24993EPSS 2.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24991: Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability

Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24991EPSS 1.9%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24985: Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability

Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24985EPSS 3.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24984: Microsoft Windows NTFS Information Disclosure Vulnerability

Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24984EPSS 1.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24983: Microsoft Windows Win32k Use-After-Free Vulnerability

Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24983EPSS 1.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-26633: Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability

Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-26633EPSS 31.9%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2018-8639: Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability

Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2018-8639EPSS 22.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-21418: Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability

Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2025-21418EPSS 1.5%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-21391: Microsoft Windows Storage Link Following Vulnerability

Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2025-21391EPSS 2.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-43451: Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability

Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this hash to impersonate that user. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-43451EPSS 81.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-49039: Microsoft Windows Task Scheduler Privilege Escalation Vulnerability

Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-49039EPSS 13.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-43573: Microsoft Windows MSHTML Platform Spoofing Vulnerability

Microsoft Windows MSHTML Platform contains an unspecified spoofing vulnerability which can lead to a loss of confidentiality. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-43573EPSS 43.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-43461: Microsoft Windows MSHTML Platform Spoofing Vulnerability

Microsoft Windows MSHTML Platform contains a user interface (UI) misrepresentation of critical information vulnerability that allows an attacker to spoof a web page. This vulnerability was exploited in conjunction with CVE-2024-38112. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38112CVE-2024-43461EPSS 84.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38217: Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability

Microsoft Windows Mark of the Web (MOTW) contains a protection mechanism failure vulnerability that allows an attacker to bypass MOTW-based defenses. This can result in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38217EPSS 9.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38107: Microsoft Windows Power Dependency Coordinator Privilege Escalation Vulnerability

Microsoft Windows Power Dependency Coordinator contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to obtain SYSTEM privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38107EPSS 1.6%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38106: Microsoft Windows Kernel Privilege Escalation Vulnerability

Microsoft Windows Kernel contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Successful exploitation of this vulnerability requires an attacker to win a race condition. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38106EPSS 6.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38193: Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability

Microsoft Windows Ancillary Function Driver for WinSock contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38193EPSS 27.6%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38213: Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience via a malicious file. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38213EPSS 13.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38178: Microsoft Windows Scripting Engine Memory Corruption Vulnerability

Microsoft Windows Scripting Engine contains a memory corruption vulnerability that allows unauthenticated attacker to initiate remote code execution via a specially crafted URL. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38178EPSS 39.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0824: Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability

Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2018-0824EPSS 73.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38112: Microsoft Windows MSHTML Platform Spoofing Vulnerability

Microsoft Windows MSHTML Platform contains a spoofing vulnerability that has a high impact to confidentiality, integrity, and availability. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38112EPSS 84.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2022-38028: Microsoft Windows Print Spooler Privilege Escalation Vulnerability

Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2022-38028EPSS 14.9%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-21338: Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability

Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-21338EPSS 51.9%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2024-21351: Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience and inject code to potentially gain code execution, which could lead to some data exposure, lack of system availability, or both. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-21351EPSS 30.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2023-36025: Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-36025EPSS 88.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2023-36884: Microsoft Windows Search Remote Code Execution Vulnerability

Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-36884EPSS 99.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2010-2568: Microsoft Windows Remote Code Execution Vulnerability

Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully exploited this vulnerability could execute code as the logged-on user. Required action: Apply updates per vendor instructions.

CVE-2010-2568EPSS 91.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2022-26925: Microsoft Windows LSA Spoofing Vulnerability

Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM. Required action: Apply remediation actions outlined in CISA guidance [https://www.cisa.gov/guidance-applying-june-microsoft-patch].

CVE-2022-26925EPSS 10.5%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2022-30190: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application. Required action: Apply updates per vendor instructions.

CVE-2022-30190EPSS 99.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1027: Microsoft Windows Kernel Privilege Escalation Vulnerability

An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. Required action: Apply updates per vendor instructions.

CVE-2020-1027EPSS 4.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0880: Microsoft Windows Privilege Escalation Vulnerability

A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity. Required action: Apply updates per vendor instructions.

CVE-2019-0880EPSS 2.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2019-1322: Microsoft Windows Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. Required action: Apply updates per vendor instructions.

CVE-2019-1322EPSS 19.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0543: Microsoft Windows Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. Required action: Apply updates per vendor instructions.

CVE-2019-0543EPSS 4.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2016-3309: Microsoft Windows Kernel Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. Required action: Apply updates per vendor instructions.

CVE-2016-3309EPSS 20.6%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2016-0099: Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability

A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator. Required action: Apply updates per vendor instructions.

CVE-2016-0099EPSS 37.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2010-0232: Microsoft Windows Kernel Exception Handler Vulnerability

The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges. Required action: Apply updates per vendor instructions.

CVE-2010-0232EPSS 29.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2002-0367: Microsoft Windows Privilege Escalation Vulnerability

smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges. Required action: Apply updates per vendor instructions.

CVE-2002-0367EPSS 5.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2014-1812: Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability

Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain. Required action: Apply updates per vendor instructions.

CVE-2014-1812EPSS 65.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2020-0938: Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability

Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. Required action: Apply updates per vendor instructions.

CVE-2020-0938EPSS 69.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1020: Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability

Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. Required action: Apply updates per vendor instructions.

CVE-2020-1020EPSS 65.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1464: Microsoft Windows Spoofing Vulnerability

Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files. Required action: Apply updates per vendor instructions.

CVE-2020-1464EPSS 41.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2021-34527: Microsoft Windows Print Spooler Remote Code Execution Vulnerability

Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare. Required action: Apply updates per vendor instructions.

CVE-2021-34527EPSS 99.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1350: Microsoft Windows DNS Server Remote Code Execution Vulnerability

Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed. Required action: Apply updates per vendor instructions.

CVE-2020-1350EPSS 92.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2019-1215: Microsoft Windows Privilege Escalation Vulnerability

Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code with elevated privileges. Required action: Apply updates per vendor instructions.

CVE-2019-1215EPSS 19.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2020-0601: Microsoft Windows CryptoAPI Spoofing Vulnerability

Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall. Required action: Apply updates per vendor instructions.

CVE-2020-0601EPSS 89.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC