Microsoft vendor intelligence

Microsoft Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Microsoft products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse KEVs Full KEV feed
Total KEVs
410
Known exploited vulnerabilities affecting Microsoft products
In CISA KEV
389
Records also listed in the official catalog
Beyond CISA KEV
21
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
7
Microsoft KEVs with sensor-observed exploitation activity

The catalog gap matters for Microsoft exposure

21 of the 410 exploited Microsoft vulnerabilities tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 5% of this vendor portfolio.

95%
Covered by CISA
5%
Beyond CISA
211
Product families

Attested Microsoft vulnerabilities

410 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2019-1429

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting...

Internet Explorer 9, Internet Explorer 11, Internet Explorer 11 on Windows Server 2012, Internet Explorer 11 on Windows 10 Version 1903 for 32-bit Systems, Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systems, Internet Explorer 11 on Windows 10 Version 1903 for ARM64-based Systems, Internet Explorer 10 Confirmed In CISA 03 Nov 2021
CVE-2020-1380

Scripting Engine Memory Corruption Vulnerability

Internet Explorer 11 Confirmed In CISA 03 Nov 2021
CVE-2017-0199

Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server...

Office/WordPad Confirmed In CISA 03 Nov 2021
CVE-2019-1367

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting...

Internet Explorer 9, Internet Explorer 11, Internet Explorer 11 on Windows Server 2012, Internet Explorer 11 on Windows 10 Version 1903 for 32-bit Systems, Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systems, Internet Explorer 11 on Windows 10 Version 1903 for ARM64-based Systems, Internet Explorer 10 Confirmed In CISA 03 Nov 2021
CVE-2021-27059

Microsoft Office Remote Code Execution Vulnerability

Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, Microsoft Office 2016 Confirmed In CISA 03 Nov 2021
CVE-2020-0674

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting...

Internet Explorer 10, Internet Explorer 11, Internet Explorer 11 on Windows 10 Version 1909 for 32-bit Systems, Internet Explorer 11 on Windows 10 Version 1909 for x64-based Systems, Internet Explorer 11 on Windows 10 Version 1909 for ARM64-based Systems, Internet Explorer 11 on Windows 10 Version 1903 for 32-bit Systems, Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systems, Internet Explorer 11 on Windows 10 Version 1903 for ARM64-based Systems, Internet Explorer 11 on Windows Server 2012, Internet Explorer 9 Confirmed In CISA 03 Nov 2021
CVE-2017-11882

Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow...

Microsoft Office Confirmed In CISA 03 Nov 2021
CVE-2019-0541

A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution...

Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office Confirmed In CISA 03 Nov 2021
CVE-2021-27085

Internet Explorer Remote Code Execution Vulnerability

Internet Explorer 11 Confirmed In CISA 03 Nov 2021
CVE-2015-1641

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word...

Word Confirmed In CISA 03 Nov 2021
CVE-2012-0158

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003...

Office Confirmed In CISA 03 Nov 2021
CVE-2018-0802

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution...

Equation Editor Confirmed In CISA 03 Nov 2021
CVE-2018-0798

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution...

Equation Editor Confirmed In CISA 03 Nov 2021
CVE-2019-1215

An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege...

Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) Confirmed In CISA 03 Nov 2021
CVE-2021-36942

Windows LSA Spoofing Vulnerability

Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server version 2004, Windows Server version 20H2 Confirmed In CISA 03 Nov 2021
CVE-2019-0797

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k...

Windows Server, Windows Confirmed In CISA 03 Nov 2021
CVE-2018-8653

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting...

Internet Explorer 9, Internet Explorer 11, Internet Explorer 10 Confirmed In CISA 03 Nov 2021
CVE-2017-8759

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or...

Microsoft .NET Framework Confirmed In CISA 03 Nov 2021
CVE-2021-40444

Microsoft MSHTML Remote Code Execution Vulnerability

Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server version 2004, Windows Server version 20H2 Confirmed In CISA 03 Nov 2021
CVE-2019-0859

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k...

Windows, Windows Server Confirmed In CISA 03 Nov 2021
CVE-2021-26411

Internet Explorer Memory Corruption Vulnerability

Internet Explorer 11, Internet Explorer 9, Microsoft Edge (EdgeHTML-based) Confirmed In CISA 03 Nov 2021
CVE-2020-1350

A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS...

Windows Server, Windows Server, version 1909 (Server Core installation), Windows Server, version 1903 (Server Core installation), Windows Server, version 2004 (Server Core installation) Confirmed In CISA 03 Nov 2021
CVE-2021-28310

Win32k Elevation of Privilege Vulnerability

Windows 10 Version 1803, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows Server, version 1909 (Server Core installation), Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2 Confirmed In CISA 03 Nov 2021
CVE-2020-1040

A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated...

Windows Server Confirmed In CISA 03 Nov 2021
CVE-2019-0803

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k...

Windows, Windows Server Confirmed In CISA 03 Nov 2021
CVE-2021-31207

Microsoft Exchange Server Security Feature Bypass Vulnerability

Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 9, Microsoft Exchange Server 2016 Cumulative Update 20, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2019 Cumulative Update 8 Confirmed In CISA 03 Nov 2021
CVE-2021-34527

Windows Print Spooler Remote Code Execution Vulnerability

Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 20H2, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server version 20H2 Confirmed In CISA 03 Nov 2021
CVE-2021-1732

Windows Win32k Elevation of Privilege Vulnerability

Windows 10 Version 1803, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows Server, version 1909 (Server Core installation), Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2 Confirmed In CISA 03 Nov 2021
CVE-2020-1464

Windows Spoofing Vulnerability

Windows 10 Version 1803, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1709 for 32-bit Systems, Windows 10 Version 1709, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) Confirmed In CISA 03 Nov 2021
CVE-2021-34473

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2016 Cumulative Update 20, Microsoft Exchange Server 2019 Cumulative Update 8, Microsoft Exchange Server 2019 Cumulative Update 9 Confirmed In CISA 03 Nov 2021
CVE-2019-0708

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker...

Windows, Windows Server Confirmed In CISA 03 Nov 2021
CVE-2016-7255

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold...

Windows Confirmed In CISA 03 Nov 2021
CVE-2017-0143

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;...

Windows SMB Confirmed In CISA 03 Nov 2021
CVE-2020-0688

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka...

Microsoft Exchange Server 2013, Microsoft Exchange Server 2019 Cumulative Update 3, Microsoft Exchange Server 2016 Cumulative Update 14, Microsoft Exchange Server 2016 Cumulative Update 15, Microsoft Exchange Server 2019 Cumulative Update 4, Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 30 Confirmed In CISA 03 Nov 2021
CVE-2021-38649

Open Management Infrastructure Elevation of Privilege Vulnerability

Azure Automation State Configuration, DSC Extension, Azure Automation Update Management, Azure Diagnostics (LAD), Azure Security Center, Azure Sentinel, Azure Stack Hub, Container Monitoring Solution, Log Analytics Agent, Open Management Infrastructure, System Center Operations Manager (SCOM) Confirmed In CISA 03 Nov 2021
CVE-2021-36948

Windows Update Medic Service Elevation of Privilege Vulnerability

Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server version 2004, Windows Server version 20H2 Confirmed In CISA 03 Nov 2021
CVE-2017-7269

Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server...

Internet Information Services (IIS) Confirmed In CISA 03 Nov 2021
CVE-2021-34523

Microsoft Exchange Server Elevation of Privilege Vulnerability

Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2016 Cumulative Update 20, Microsoft Exchange Server 2019 Cumulative Update 8, Microsoft Exchange Server 2019 Cumulative Update 9 Confirmed In CISA 03 Nov 2021
CVE-2021-38645

Open Management Infrastructure Elevation of Privilege Vulnerability

Azure Automation State Configuration, DSC Extension, Azure Automation Update Management, Azure Diagnostics (LAD), Azure Security Center, Azure Sentinel, Azure Stack Hub, Container Monitoring Solution, Log Analytics Agent, Open Management Infrastructure, System Center Operations Manager (SCOM) Confirmed In CISA 03 Nov 2021
CVE-2020-1020

A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a...

Windows, Windows Server, Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) Confirmed In CISA 03 Nov 2021
CVE-2020-0986

An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of...

Windows, Windows Server, Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 2004 for 32-bit Systems, Windows Server, version 2004 (Server Core installation), Windows 10 Version 2004 for ARM64-based Systems, Windows 10 Version 2004 for x64-based Systems Confirmed In CISA 03 Nov 2021
CVE-2020-17144

Microsoft Exchange Remote Code Execution Vulnerability

Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 31 Confirmed In CISA 03 Nov 2021
CVE-2020-0938

A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a...

Windows, Windows Server, Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) Confirmed In CISA 03 Nov 2021
CVE-2021-31979

Windows Kernel Elevation of Privilege Vulnerability

Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server version 2004, Windows Server version 20H2 Confirmed In CISA 03 Nov 2021
CVE-2021-31201

Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) Confirmed In CISA 03 Nov 2021
CVE-2021-31956

Windows NTFS Elevation of Privilege Vulnerability

Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) Confirmed In CISA 03 Nov 2021
CVE-2021-33771

Windows Kernel Elevation of Privilege Vulnerability

Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 8.1, Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server version 2004, Windows Server version 20H2 Confirmed In CISA 03 Nov 2021
CVE-2021-31199

Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) Confirmed In CISA 03 Nov 2021
CVE-2021-33742

Windows MSHTML Platform Remote Code Execution Vulnerability

Windows 10 Version 1809, Windows Server 2019, Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2012, Windows Server 2012 R2 Confirmed In CISA 03 Nov 2021
CVE-2020-17087

Windows Kernel Local Elevation of Privilege Vulnerability

Windows 10 Version 1803, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) Confirmed In CISA 03 Nov 2021

Showing 50 of 50 on this page (410 Microsoft known exploited vulnerabilities).

Recurring weakness patterns

Out-of-bounds write, use after free, and link resolution before file access ('link following') account for 99 mapped occurrences across this Microsoft KEV portfolio.

Browse all KEVs →