Microsoft vendor intelligence
Microsoft Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Microsoft products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 410
- Known exploited vulnerabilities affecting Microsoft products
- In CISA KEV
- 389
- Records also listed in the official catalog
- Beyond CISA KEV
- 21
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 7
- Microsoft KEVs with sensor-observed exploitation activity
The catalog gap matters for Microsoft exposure
21 of the 410 exploited Microsoft vulnerabilities tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 5% of this vendor portfolio.
- 95%
- Covered by CISA
- 5%
- Beyond CISA
- 211
- Product families
Attested Microsoft vulnerabilities
410 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2019-1429
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting... |
Internet Explorer 9, Internet Explorer 11, Internet Explorer 11 on Windows Server 2012, Internet Explorer 11 on Windows 10 Version 1903 for 32-bit Systems, Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systems, Internet Explorer 11 on Windows 10 Version 1903 for ARM64-based Systems, Internet Explorer 10 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-1380
Scripting Engine Memory Corruption Vulnerability |
Internet Explorer 11 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2017-0199
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server... |
Office/WordPad | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-1367
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting... |
Internet Explorer 9, Internet Explorer 11, Internet Explorer 11 on Windows Server 2012, Internet Explorer 11 on Windows 10 Version 1903 for 32-bit Systems, Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systems, Internet Explorer 11 on Windows 10 Version 1903 for ARM64-based Systems, Internet Explorer 10 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-27059
Microsoft Office Remote Code Execution Vulnerability |
Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, Microsoft Office 2016 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-0674
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting... |
Internet Explorer 10, Internet Explorer 11, Internet Explorer 11 on Windows 10 Version 1909 for 32-bit Systems, Internet Explorer 11 on Windows 10 Version 1909 for x64-based Systems, Internet Explorer 11 on Windows 10 Version 1909 for ARM64-based Systems, Internet Explorer 11 on Windows 10 Version 1903 for 32-bit Systems, Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systems, Internet Explorer 11 on Windows 10 Version 1903 for ARM64-based Systems, Internet Explorer 11 on Windows Server 2012, Internet Explorer 9 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2017-11882
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow... |
Microsoft Office | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-0541
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution... |
Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-27085
Internet Explorer Remote Code Execution Vulnerability |
Internet Explorer 11 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2015-1641
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word... |
Word | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2012-0158
The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003... |
Office | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2018-0802
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution... |
Equation Editor | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2018-0798
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution... |
Equation Editor | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-1215
An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege... |
Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-36942
Windows LSA Spoofing Vulnerability |
Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server version 2004, Windows Server version 20H2 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-0797
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k... |
Windows Server, Windows | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2018-8653
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting... |
Internet Explorer 9, Internet Explorer 11, Internet Explorer 10 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2017-8759
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or... |
Microsoft .NET Framework | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-40444
Microsoft MSHTML Remote Code Execution Vulnerability |
Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server version 2004, Windows Server version 20H2 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-0859
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k... |
Windows, Windows Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-26411
Internet Explorer Memory Corruption Vulnerability |
Internet Explorer 11, Internet Explorer 9, Microsoft Edge (EdgeHTML-based) | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-1350
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS... |
Windows Server, Windows Server, version 1909 (Server Core installation), Windows Server, version 1903 (Server Core installation), Windows Server, version 2004 (Server Core installation) | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-28310
Win32k Elevation of Privilege Vulnerability |
Windows 10 Version 1803, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows Server, version 1909 (Server Core installation), Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-1040
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated... |
Windows Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-0803
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k... |
Windows, Windows Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-31207
Microsoft Exchange Server Security Feature Bypass Vulnerability |
Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 9, Microsoft Exchange Server 2016 Cumulative Update 20, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2019 Cumulative Update 8 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-34527
Windows Print Spooler Remote Code Execution Vulnerability |
Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 20H2, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server version 20H2 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-1732
Windows Win32k Elevation of Privilege Vulnerability |
Windows 10 Version 1803, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows Server, version 1909 (Server Core installation), Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-1464
Windows Spoofing Vulnerability |
Windows 10 Version 1803, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1709 for 32-bit Systems, Windows 10 Version 1709, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-34473
Microsoft Exchange Server Remote Code Execution Vulnerability |
Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2016 Cumulative Update 20, Microsoft Exchange Server 2019 Cumulative Update 8, Microsoft Exchange Server 2019 Cumulative Update 9 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-0708
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker... |
Windows, Windows Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2016-7255
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold... |
Windows | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2017-0143
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;... |
Windows SMB | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-0688
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka... |
Microsoft Exchange Server 2013, Microsoft Exchange Server 2019 Cumulative Update 3, Microsoft Exchange Server 2016 Cumulative Update 14, Microsoft Exchange Server 2016 Cumulative Update 15, Microsoft Exchange Server 2019 Cumulative Update 4, Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 30 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-38649
Open Management Infrastructure Elevation of Privilege Vulnerability |
Azure Automation State Configuration, DSC Extension, Azure Automation Update Management, Azure Diagnostics (LAD), Azure Security Center, Azure Sentinel, Azure Stack Hub, Container Monitoring Solution, Log Analytics Agent, Open Management Infrastructure, System Center Operations Manager (SCOM) | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-36948
Windows Update Medic Service Elevation of Privilege Vulnerability |
Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server version 2004, Windows Server version 20H2 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2017-7269
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server... |
Internet Information Services (IIS) | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-34523
Microsoft Exchange Server Elevation of Privilege Vulnerability |
Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2016 Cumulative Update 20, Microsoft Exchange Server 2019 Cumulative Update 8, Microsoft Exchange Server 2019 Cumulative Update 9 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-38645
Open Management Infrastructure Elevation of Privilege Vulnerability |
Azure Automation State Configuration, DSC Extension, Azure Automation Update Management, Azure Diagnostics (LAD), Azure Security Center, Azure Sentinel, Azure Stack Hub, Container Monitoring Solution, Log Analytics Agent, Open Management Infrastructure, System Center Operations Manager (SCOM) | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-1020
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a... |
Windows, Windows Server, Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-0986
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of... |
Windows, Windows Server, Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 2004 for 32-bit Systems, Windows Server, version 2004 (Server Core installation), Windows 10 Version 2004 for ARM64-based Systems, Windows 10 Version 2004 for x64-based Systems | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-17144
Microsoft Exchange Remote Code Execution Vulnerability |
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 31 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-0938
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a... |
Windows, Windows Server, Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-31979
Windows Kernel Elevation of Privilege Vulnerability |
Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server version 2004, Windows Server version 20H2 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-31201
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability |
Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-31956
Windows NTFS Elevation of Privilege Vulnerability |
Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-33771
Windows Kernel Elevation of Privilege Vulnerability |
Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 8.1, Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server version 2004, Windows Server version 20H2 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-31199
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability |
Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-33742
Windows MSHTML Platform Remote Code Execution Vulnerability |
Windows 10 Version 1809, Windows Server 2019, Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2012, Windows Server 2012 R2 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-17087
Windows Kernel Local Elevation of Privilege Vulnerability |
Windows 10 Version 1803, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | Confirmed | In CISA | 03 Nov 2021 |
No Microsoft vulnerabilities match this search or filter.
Showing 50 of 50 on this page (410 Microsoft known exploited vulnerabilities).
Recurring weakness patterns
Out-of-bounds write, use after free, and link resolution before file access ('link following') account for 99 mapped occurrences across this Microsoft KEV portfolio.
CWE-787
Out-of-bounds Write
CWE-416
Use After Free
CWE-59
Improper Link Resolution Before File Access ('Link Following')
CWE-20
Improper Input Validation
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
CWE-94
Improper Control of Generation of Code ('Code Injection')
CWE-502
Deserialization of Untrusted Data
CWE-122
Heap-based Buffer Overflow