VendorsMicrosoftwindows_7any version
Vulnerabilities

Microsoft Windows 7 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3056CVEs
CVE-2011-1881
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
Published 2011-07-13 · Modified
8.4EPSS 0.013
CVE-2012-1867
Integer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted TrueType font file that triggers incorrect memory allocation, aka "Font Resource Refcount Integer Overflow Vulnerability."
Published 2012-06-12 · Modified
8.4EPSS 0.012
CVE-2013-3888
dxgkrnl.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "DirectX Graphics Kernel Subsystem Double Fetch Vulnerability."
Published 2013-10-09 · Modified
8.4EPSS 0.010
CVE-2015-0008
The UNC implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not include authentication from the server to the client, which allows remote attackers to execute arbitrary code by making crafted data available on a UNC share, as demonstrated by Group Policy data from a spoofed domain controller, aka "Group Policy Remote Code Execution Vulnerability."
Published 2015-02-11 · Modified
8.31 PoCEPSS 0.286
CVE-2015-2546
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2518.
Published 2015-09-09 · Analyzed
8.2KEVEPSS 0.101
CVE-2022-37958
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
8.1EPSS 0.860
CVE-2020-17140
Windows SMB Information Disclosure Vulnerability
Published 2020-12-09 · Modified
8.1EPSS 0.131
CVE-2017-0161
The Windows NetBT Session Services component on Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to maintain certain sequencing requirements, aka "NetBIOS Remote Code Execution Vulnerability".
Published 2017-09-13 · Modified
8.1EPSS 0.112
CVE-2022-26925
Windows LSA Spoofing Vulnerability
Published 2022-05-10 · Analyzed
8.1KEVEPSS 0.107
CVE-2017-8563
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Kerberos falling back to NT LAN Manager (NTLM) Authentication Protocol as the default authentication protocol, aka "Windows Elevation of Privilege Vulnerability".
Published 2017-07-11 · Modified
8.1EPSS 0.072
CVE-2021-26435
Windows Scripting Engine Memory Corruption Vulnerability
Published 2021-09-15 · Modified
8.1EPSS 0.053
CVE-2020-0665
An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privilege Vulnerability'.
Published 2020-02-11 · Modified
8.1EPSS 0.044
CVE-2019-1424
A security feature bypass vulnerability exists when Windows Netlogon improperly handles a secure communications channel, aka 'NetLogon Security Feature Bypass Vulnerability'.
Published 2019-11-12 · Modified
8.1EPSS 0.031
CVE-2021-34492
Windows Certificate Spoofing Vulnerability
Published 2021-07-14 · Modified
8.1EPSS 0.024
CVE-2022-34714
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Published 2022-08-09 · Modified
8.1EPSS 0.019
CVE-2023-21543
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
Published 2023-01-10 · Modified
8.1EPSS 0.017
CVE-2022-35767
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Published 2022-08-09 · Modified
8.1EPSS 0.017
CVE-2022-41081
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.1EPSS 0.016
CVE-2023-21556
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
Published 2023-01-10 · Modified
8.1EPSS 0.015
CVE-2022-38000
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.1EPSS 0.014
CVE-2022-22035
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.1EPSS 0.013
CVE-2022-34702
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Published 2022-08-09 · Modified
8.1EPSS 0.012
CVE-2022-35752
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Published 2023-05-31 · Modified
8.1EPSS 0.012
CVE-2022-35753
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Published 2023-05-31 · Modified
8.1EPSS 0.012
CVE-2022-35745
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Published 2023-05-31 · Modified
8.1EPSS 0.012
CVE-2022-30198
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.1EPSS 0.012
CVE-2022-33634
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.1EPSS 0.012
CVE-2022-24504
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.1EPSS 0.012
CVE-2022-38047
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.1EPSS 0.012
CVE-2022-44670
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Published 2022-12-13 · Modified
8.1EPSS 0.012
CVE-2022-41039
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-11-09 · Modified
8.1EPSS 0.011
CVE-2023-21679
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
Published 2023-01-10 · Modified
8.1EPSS 0.011
CVE-2023-21555
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
Published 2023-01-10 · Modified
8.1EPSS 0.011
CVE-2023-21546
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
Published 2023-01-10 · Modified
8.1EPSS 0.011
CVE-2022-44676
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Published 2022-12-13 · Modified
8.1EPSS 0.011
CVE-2023-21548
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Published 2023-01-10 · Modified
8.1EPSS 0.011
CVE-2022-41044
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-11-09 · Modified
8.1EPSS 0.011
CVE-2019-0720
Hyper-V Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
8.0EPSS 0.038
CVE-2020-1552
Windows Work Folder Service Elevation of Privilege Vulnerability
Published 2020-08-17 · Modified
8.0EPSS 0.024
CVE-2021-1726
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-02-25 · Modified
8.0EPSS 0.021
← Prev24 / 77Next →