IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

Microsoft vulnerabilities

16.469 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2002-0367 HIGH 7.8 microsoft windows_2000 smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstr 4.9%
CVE-2026-32202 MED 4.3 microsoft windows_10_1607 Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. 4.9%
CVE-2009-1123 HIGH 7.8 microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, ak 4.9%
CVE-2026-21525 MED 6.2 microsoft windows_10_1607 Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally. 4.8%
CVE-2019-0543 HIGH 7.8 ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft Windows Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows S 4.7%
CVE-2025-60710 HIGH 7.8 ransomware microsoft windows_11_24h2 Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally. 4.6%
CVE-2020-1027 HIGH 7.8 microsoft windows_10_1507 An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1000, CVE-2020-1003. 4.5%
CVE-2021-31979 HIGH 7.8 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 4.5%
CVE-2018-8611 HIGH 7.8 microsoft windows_10_1607 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, W 4.2%
CVE-2023-32049 HIGH 8.8 microsoft windows_10_1607 Windows SmartScreen Security Feature Bypass Vulnerability 4.2%
CVE-2019-0859 HIGH 7.8 ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0803. 4.2%
CVE-2026-21533 HIGH 7.8 microsoft windows_10_1607 Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. 4.1%
CVE-2015-1769 MED 6.6 microsoft windows_10 Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks, which allows physically proximate attackers t 4.1%
CVE-2021-36955 HIGH 7.8 ransomware microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability 4.0%
CVE-2024-26169 HIGH 7.8 ransomware microsoft windows_10_1507 Windows Error Reporting Service Elevation of Privilege Vulnerability 4.0%
CVE-2024-30040 HIGH 8.8 microsoft windows_10_1507 Windows MSHTML Platform Security Feature Bypass Vulnerability 3.9%
CVE-2025-24985 HIGH 7.8 microsoft windows_10_1507 Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally. 3.8%
CVE-2026-85880 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. 3.6%
CVE-2019-1385 HIGH 7.8 ransomware microsoft windows_10_1709 An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially craf 3.6%
CVE-2019-1315 HIGH 7.8 ransomware microsoft windows_10_1607 An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1339, CVE-2019-1342. 3.5%
CVE-2018-8406 HIGH 7.8 ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 3.4%
CVE-2018-8405 HIGH 7.8 ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Wind 3.4%
CVE-2017-0001 HIGH 7.8 microsoft windows_10_1507 The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a 3.1%
CVE-2021-43226 HIGH 7.8 ransomware microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability 3.1%
CVE-2023-36584 MED 5.4 microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability 3.1%