VendorsMicrosoftwindowsall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10356CVEs
CVE-2021-45440
A unnecessary privilege vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security 10.0 SP1 (on-prem versions only) could allow a local attacker to abuse an impersonation privilege and elevate to a higher level of privileges. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Published 2022-01-08 · Modified
7.8EPSS 0.005
CVE-2023-25908
Adobe Photoshop SVG file Use After Free Arbitrary code execution
Published 2023-03-27 · Modified
7.8EPSS 0.005
CVE-2017-11742
The writeRandomBytes_RtlGenRandom function in xmlparse.c in libexpat in Expat 2.2.1 and 2.2.2 on Windows allows local users to gain privileges via a Trojan horse ADVAPI32.DLL in the current working directory because of an untrusted search path, aka DLL hijacking.
Published 2017-07-30 · Modified
7.8EPSS 0.005
CVE-2023-47075
ZDI-CAN-22006: Adobe Illustrator JP2 File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2023-12-13 · Modified
7.8EPSS 0.005
CVE-2026-50650
.NET Framework Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.005
CVE-2019-7487
Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a malicious binary by an attacker within the parent path could allow code execution.
Published 2019-12-19 · Modified
7.8EPSS 0.005
CVE-2021-42101
An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar but not identical to CVE-2021-42103.
Published 2021-10-21 · Modified
7.8EPSS 0.005
CVE-2021-42103
An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar but not identical to CVE-2021-42101.
Published 2021-10-21 · Modified
7.8EPSS 0.005
CVE-2021-42102
An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service agents could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Published 2021-10-21 · Modified
7.8EPSS 0.005
CVE-2020-22722
Rapid Software LLC Rapid SCADA 5.8.0 is affected by a local privilege escalation vulnerability in the ScadaAgentSvc.exe executable file. An attacker can obtain admin privileges by placing a malicious .exe file in the application and renaming it ScadaAgentSvc.exe, which would result in executing the binary as NT AUTHORITY\SYSTEM in a Windows operating system. For example, an attacker can plant a reverse shell from a low privileged user account and by restarting the computer, the malicious service will be started as NT AUTHORITY\SYSTEM by giving the attacker full system access to the remote PC.
Published 2020-08-14 · Modified
7.8EPSS 0.005
CVE-2024-20746
Adobe Premiere Pro Out-of-bounds Write Arbitrary code execution
Published 2024-03-18 · Analyzed
7.8EPSS 0.005
CVE-2022-35675
Adobe FrameMaker SVG File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-08-11 · Modified
7.8EPSS 0.005
CVE-2024-0107
NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published 2024-08-08 · Modified
7.8EPSS 0.005
CVE-2022-35704
Adobe Bridge SVG File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-09-19 · Modified
7.8EPSS 0.005
CVE-2018-6235
An Out-of-Bounds write privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x222814 by the tmnciesc.sys driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Published 2018-05-25 · Modified
7.8EPSS 0.005
CVE-2023-2939
Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed a local attacker to perform privilege escalation via crafted symbolic link. (Chromium security severity: Medium)
Published 2023-05-30 · Modified
7.8EPSS 0.005
CVE-2025-66476
Vim for Windows Uncontrolled Search Path Element Remote Code Execution Vulnerability
Published 2025-12-02 · Analyzed
7.8EPSS 0.005
CVE-2021-1052
NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape or IOCTL in which user-mode clients can access legacy privileged APIs, which may lead to denial of service, escalation of privileges, and information disclosure.
Published 2021-01-08 · Modified
7.8EPSS 0.005
CVE-2023-41718
When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file.
Published 2023-11-14 · Modified
7.8EPSS 0.005
CVE-2024-49509
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
Published 2024-11-12 · Analyzed
7.8EPSS 0.005
CVE-2023-41613
EzViz Studio v2.2.0 is vulnerable to DLL hijacking.
Published 2023-12-04 · Modified
7.8EPSS 0.005
CVE-2022-28852
Adobe InDesign 2022 Out-of-Bound Write Arbitrary code execution
Published 2022-09-16 · Modified
7.8EPSS 0.005
CVE-2025-43577
Acrobat Reader | Use After Free (CWE-416)
Published 2025-06-10 · Analyzed
7.8EPSS 0.005
CVE-2025-43550
Acrobat Reader | Use After Free (CWE-416)
Published 2025-06-10 · Analyzed
7.8EPSS 0.005
CVE-2022-28853
Adobe InDesign 2022 Out-of-Bound Write Arbitrary code execution
Published 2022-09-16 · Modified
7.8EPSS 0.005
CVE-2018-1834
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to escalate their privileges to root through a symbolic link attack. IBM X-Force ID: 150511.
Published 2018-11-09 · Modified
7.8EPSS 0.005
CVE-2017-11159
Multiple untrusted search path vulnerabilities in installer in Synology Photo Station Uploader before 1.4.2-084 on Windows allows local attackers to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current working directory.
Published 2017-08-23 · Modified
7.8EPSS 0.004
CVE-2024-43373
webcrack has an Arbitrary File Write Vulnerability on Windows when Parsing and Saving a Malicious Bundle
Published 2024-08-15 · Analyzed
7.8EPSS 0.004
CVE-2025-27158
Acrobat Reader | Access of Uninitialized Pointer (CWE-824)
Published 2025-03-11 · Analyzed
7.8EPSS 0.004
CVE-2021-42714
Splashtop Remote Client (Business Edition) through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions.
Published 2022-02-15 · Modified
7.8EPSS 0.004
CVE-2019-5670
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiEscape in which the software uses a sequential operation to read from or write to a buffer, but it uses an incorrect length value that causes it to access memory that is outside of the bounds of the buffer which may lead to denial of service, escalation of privileges, code execution or information disclosure.
Published 2019-02-27 · Modified
7.8EPSS 0.004
CVE-2025-43574
Acrobat Reader | Use After Free (CWE-416)
Published 2025-06-10 · Analyzed
7.8EPSS 0.004
CVE-2025-43573
Acrobat Reader | Use After Free (CWE-416)
Published 2025-06-10 · Analyzed
7.8EPSS 0.004
CVE-2022-28832
Adobe InDesign Font Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2023-09-11 · Modified
7.8EPSS 0.004
CVE-2019-10128
A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the default configuration, this allows a local attacker to read arbitrary data directory files, essentially bypassing database-imposed read access limitations. In plausible non-default configurations, an attacker having both an unprivileged Windows account and an unprivileged PostgreSQL account can cause the PostgreSQL service account to execute arbitrary code.
Published 2021-03-19 · Modified
7.8EPSS 0.004
CVE-2019-5667
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiSetRootPageTable in which the application dereferences a pointer that it expects to be valid, but is NULL, which may lead to code execution, denial of service or escalation of privileges.
Published 2019-02-27 · Modified
7.8EPSS 0.004
CVE-2024-52982
Animate | Improper Input Validation (CWE-20)
Published 2024-12-10 · Analyzed
7.8EPSS 0.004
CVE-2017-11157
Multiple untrusted search path vulnerabilities in the installer in Synology Cloud Station Backup before 4.2.5-4396 on Windows allow local attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current working directory.
Published 2017-08-30 · Modified
7.8EPSS 0.004
CVE-2017-6272
NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where a value passed from a user to the driver is not correctly validated and used as the index to an array which may lead to a denial of service or possible escalation of privileges.
Published 2017-09-22 · Modified
7.8EPSS 0.004
CVE-2024-39388
ZDI-CAN-24055: Adobe Substance 3D Stager SKP File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2024-08-14 · Analyzed
7.8EPSS 0.004
← Prev130 / 259Next →