VendorsMicrosoftwindows_7any version
Vulnerabilities

Microsoft Windows 7 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3056CVEs
CVE-2022-44697
Windows Graphics Component Elevation of Privilege Vulnerability
Published 2022-12-13 · Modified
7.8EPSS 0.005
CVE-2021-43248
Windows Digital Media Receiver Elevation of Privilege Vulnerability
Published 2021-12-15 · Modified
7.8EPSS 0.005
CVE-2021-43223
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Published 2021-12-15 · Modified
7.8EPSS 0.005
CVE-2021-43245
Windows Digital TV Tuner Elevation of Privilege Vulnerability
Published 2021-12-15 · Modified
7.8EPSS 0.005
CVE-2023-21537
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.8EPSS 0.005
CVE-2022-37992
Windows Group Policy Elevation of Privilege Vulnerability
Published 2022-11-09 · Modified
7.8EPSS 0.005
CVE-2021-36927
Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability
Published 2021-08-12 · Modified
7.8EPSS 0.005
CVE-2021-31193
Windows SSDP Service Elevation of Privilege Vulnerability
Published 2021-05-11 · Modified
7.8EPSS 0.005
CVE-2021-36964
Windows Event Tracing Elevation of Privilege Vulnerability
Published 2021-09-15 · Modified
7.8EPSS 0.005
CVE-2021-38628
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published 2021-09-15 · Modified
7.8EPSS 0.005
CVE-2021-38638
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published 2021-09-15 · Modified
7.8EPSS 0.005
CVE-2021-38630
Windows Event Tracing Elevation of Privilege Vulnerability
Published 2021-09-15 · Modified
7.8EPSS 0.005
CVE-2023-21730
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.8EPSS 0.005
CVE-2022-41095
Windows Digital Media Receiver Elevation of Privilege Vulnerability
Published 2022-11-09 · Modified
7.8EPSS 0.005
CVE-2022-41094
Windows Hyper-V Elevation of Privilege Vulnerability
Published 2022-12-13 · Modified
7.8EPSS 0.005
CVE-2022-37986
Windows Win32k Elevation of Privilege Vulnerability
Published 2022-10-11 · Modified
7.8EPSS 0.005
CVE-2023-21755
Windows Kernel Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.8EPSS 0.005
CVE-2021-41367
NTFS Elevation of Privilege Vulnerability
Published 2021-11-10 · Modified
7.8EPSS 0.005
CVE-2021-41377
Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
Published 2021-11-10 · Modified
7.8EPSS 0.005
CVE-2021-41370
NTFS Elevation of Privilege Vulnerability
Published 2021-11-10 · Modified
7.8EPSS 0.005
CVE-2023-21726
Windows Credential Manager User Interface Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.8EPSS 0.005
CVE-2023-21680
Windows Win32k Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.8EPSS 0.005
CVE-2023-21765
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.8EPSS 0.005
CVE-2023-21754
Windows Kernel Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.8EPSS 0.005
CVE-2022-34706
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
Published 2022-08-09 · Modified
7.8EPSS 0.004
CVE-2023-21561
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.8EPSS 0.004
CVE-2018-18913
Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive composed of an HTML page along with a malicious DLL to the target. Once the document is opened, it may allow the attacker to take full control of the system from any location within the system. The issue lies in the loading of the shcore.dll and dcomp.dll files: these files are being searched for by the program in the same system-wide directory where the HTML file is executed.
Published 2019-03-21 · Modified
7.8EPSS 0.004
CVE-2023-21524
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.8EPSS 0.004
CVE-2018-16098
In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user.
Published 2019-01-24 · Modified
7.8EPSS 0.004
CVE-2017-3762
Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a hard-coded password, and is accessible to all users with local non-administrative access to the system in which it is installed.
Published 2018-01-26 · Modified
7.8EPSS 0.004
CVE-2017-3756
A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path.
Published 2017-08-18 · Modified
7.8EPSS 0.004
CVE-2022-41045
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Published 2022-11-09 · Modified
7.8EPSS 0.003
CVE-2018-6265
NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 during application installation on Windows 7 in elevated privilege mode, where a local user who initiates a browser session may obtain escalation of privileges on the browser.
Published 2018-11-27 · Modified
7.8EPSS 0.003
CVE-2020-0559
Insecure inherited permissions in some Intel(R) PROSet/Wireless WiFi products on Windows* 7 and 8.1 before version 21.40.5.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
Published 2020-08-13 · Modified
7.8EPSS 0.003
CVE-2022-42972
A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a local attacker modifies the webroot directory. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)
Published 2023-02-01 · Modified
7.8EPSS 0.002
CVE-2022-42973
A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local attacker connects to the database. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)
Published 2023-02-01 · Modified
7.8EPSS 0.002
CVE-2021-30605
Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls.
Published 2021-09-08 · Modified
7.8EPSS 0.001
CVE-2011-1271
The JIT compiler in Microsoft .NET Framework 3.5 Gold and SP1, 3.5.1, and 4.0, when IsJITOptimizerDisabled is false, does not properly handle expressions related to null strings, which allows context-dependent attackers to bypass intended access restrictions, and consequently execute arbitrary code, in opportunistic circumstances by leveraging a crafted application, as demonstrated by (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework JIT Optimization Vulnerability."
Published 2011-05-10 · Modified
7.71 PoCEPSS 0.201
CVE-2021-34500
Windows Kernel Memory Information Disclosure Vulnerability
Published 2021-07-14 · Modified
7.7EPSS 0.026
CVE-2016-0189
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.
Published 2016-05-11 · Analyzed
7.6KEV1 PoCEPSS 0.941
← Prev41 / 77Next →