IT
56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2017-11782 HIGH 7.8 microsoft windows_10 The Microsoft Server Block Message (SMB) on Microsoft Windows 10 1607 and Windows Server 2016, allows an elevation of privilege vulnerability when an attacker sends specially crafted requests to the server, aka "Windows SMB Elevation of Privilege Vulnerability 1.2%
CVE-2017-8503 HIGH 8.8 microsoft edge Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to escape from the AppContainer sandbox, aka "Microsoft Edge Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8642. 1.2%
CVE-2011-1236 HIGH 7.8 microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain 1.2%
CVE-2023-36871 MED 6.5 microsoft windows_10_1507 Azure Active Directory Security Feature Bypass Vulnerability 1.2%
CVE-2011-1887 HIGH 7.8 microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a 1.2%
CVE-2025-27481 HIGH 8.8 microsoft windows_10_1507 Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. 1.2%
CVE-2025-27471 MED 5.9 microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2023-29352 MED 6.5 microsoft remote_desktop_client Windows Remote Desktop Security Feature Bypass Vulnerability 1.2%
CVE-1999-0824 MED 4.6 microsoft windows_nt A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users. 1.2%
CVE-1999-0384 MED 4.6 microsoft office The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content. 1.2%
CVE-2025-24994 HIGH 7.3 microsoft windows_11_22h2 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. 1.2%
CVE-2013-1283 MED 6.9 microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows loca 1.2%
CVE-2023-28290 MED 5.3 microsoft remote_desktop_app Microsoft Remote Desktop app for Windows Information Disclosure Vulnerability 1.2%
CVE-2022-30175 HIGH 7.8 microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability 1.2%
CVE-2021-26431 HIGH 7.8 microsoft windows_10 Windows Recovery Environment Agent Elevation of Privilege Vulnerability 1.2%
CVE-2020-1398 MED 6.8 microsoft windows_10 An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly handle Ease of Access dialog.An attacker who successfully exploited the vulnerability could execute commands with elevated permissions.The security update addresses the vu 1.2%
CVE-2019-1065 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, 1.2%
CVE-2017-11818 MED 4.5 microsoft windows_10 The Microsoft Windows Storage component on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass vulnerability when it fails to validate an integrity-level 1.2%
CVE-2026-54118 CRIT 9.8 microsoft sql_server_2016 Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. 1.2%
CVE-2026-54117 CRIT 9.8 microsoft sql_server_2016 Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. 1.2%
CVE-2026-35435 HIGH 8.6 microsoft azure_ai_foundry Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. 1.2%
CVE-2024-38089 CRIT 9.1 microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability 1.2%
CVE-2023-28271 MED 5.5 microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability 1.2%
CVE-2022-23269 MED 5.4 microsoft dynamics_gp Microsoft Dynamics GP Spoofing Vulnerability 1.2%
CVE-2020-24003 LOW 3.3 microsoft skype Microsoft Skype through 8.59.0.77 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Skype Cli 1.2%