VendorsMicrosoftwindows_8.1all versions
Vulnerabilities

Microsoft Windows 8.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2873CVEs
CVE-2022-26903
Windows Graphics Component Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.3EPSS 0.027
CVE-2022-30141
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-06-15 · Modified
9.3EPSS 0.026
CVE-2022-26919
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.3EPSS 0.026
CVE-2017-10855
Untrusted search path vulnerability in FENCE-Explorer for Windows V8.4.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published 2017-09-15 · Modified
9.3EPSS 0.011
CVE-2019-0719
A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0721.
Published 2019-11-12 · Modified
9.1EPSS 0.114
CVE-2023-21557
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
Published 2023-01-10 · Modified
9.1EPSS 0.020
CVE-2014-6324
The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote authenticated domain users to obtain domain administrator privileges via a forged signature in a ticket, as exploited in the wild in November 2014, aka "Kerberos Checksum Vulnerability."
Published 2014-11-18 · Analyzed
9.0KEV1 PoCEPSS 0.873
CVE-2022-26923
Active Directory Domain Services Elevation of Privilege Vulnerability
Published 2022-05-10 · Analyzed
9.0KEVEPSS 0.835
CVE-2014-1812
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly handle distribution of passwords, which allows remote authenticated users to obtain sensitive credential information and consequently gain privileges by leveraging access to the SYSVOL share, as exploited in the wild in May 2014, aka "Group Policy Preferences Password Elevation of Privilege Vulnerability."
Published 2014-05-14 · Analyzed
9.0KEVEPSS 0.649
CVE-2016-3345
The SMBv1 server in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Authenticated Remote Code Execution Vulnerability."
Published 2016-09-14 · Modified
9.0EPSS 0.325
CVE-2020-17096
Windows NTFS Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
9.0EPSS 0.195
CVE-2019-0856
A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.
Published 2019-04-09 · Modified
9.0EPSS 0.194
CVE-2016-3368
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow remote authenticated users to execute arbitrary code by leveraging a domain account to make a crafted request, aka "Windows Remote Code Execution Vulnerability."
Published 2016-09-14 · Modified
9.0EPSS 0.183
CVE-2019-0630
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0633.
Published 2019-03-06 · Modified
9.0EPSS 0.174
CVE-2016-0178
The RPC NDR Engine in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandles free operations, which allows remote attackers to execute arbitrary code via malformed RPC requests, aka "RPC Network Data Representation Engine Elevation of Privilege Vulnerability."
Published 2016-05-11 · Modified
9.0EPSS 0.167
CVE-2018-8450
A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-11-14 · Modified
9.0EPSS 0.161
CVE-2020-0662
A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.
Published 2020-02-11 · Modified
9.0EPSS 0.133
CVE-2019-0633
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0630.
Published 2019-03-06 · Modified
9.0EPSS 0.130
CVE-2019-0722
Windows Hyper-V Remote Code Execution Vulnerability
Published 2019-06-12 · Modified
9.0EPSS 0.047
CVE-2020-1317
An elevation of privilege vulnerability exists when Group Policy improperly checks access, aka 'Group Policy Elevation of Privilege Vulnerability'.
Published 2020-06-09 · Modified
9.0EPSS 0.044
CVE-2021-1667
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2021-01-12 · Modified
9.0EPSS 0.036
CVE-2021-1700
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2021-01-12 · Modified
9.0EPSS 0.036
CVE-2021-1701
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2021-01-12 · Modified
9.0EPSS 0.036
CVE-2022-23284
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2022-03-09 · Modified
9.0EPSS 0.032
CVE-2022-29131
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.0EPSS 0.028
CVE-2022-29129
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.0EPSS 0.028
CVE-2022-29128
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.0EPSS 0.028
CVE-2022-21922
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.0EPSS 0.028
CVE-2022-21920
Windows Kerberos Elevation of Privilege Vulnerability
Published 2022-01-11 · Modified
9.0EPSS 0.028
CVE-2020-1067
A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.
Published 2020-05-21 · Modified
9.0EPSS 0.025
CVE-2022-21857
Active Directory Domain Services Elevation of Privilege Vulnerability
Published 2022-01-11 · Modified
9.0EPSS 0.025
CVE-2021-1706
Windows LUAFV Elevation of Privilege Vulnerability
Published 2021-01-12 · Modified
9.0EPSS 0.021
CVE-2022-21901
Windows Hyper-V Elevation of Privilege Vulnerability
Published 2022-01-11 · Modified
9.0EPSS 0.009
CVE-2021-40444
Microsoft MSHTML Remote Code Execution Vulnerability
Published 2021-09-15 · Analyzed
8.8KEVEPSS 0.975
CVE-2021-26411
Internet Explorer Memory Corruption Vulnerability
Published 2021-03-11 · Analyzed
8.8KEVEPSS 0.808
CVE-2018-0824
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-05-09 · Analyzed
8.8KEV1 PoCEPSS 0.732
CVE-2020-1020
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0938.
Published 2020-04-15 · Analyzed
8.8KEVEPSS 0.650
CVE-2021-33742
Windows MSHTML Platform Remote Code Execution Vulnerability
Published 2021-06-08 · Analyzed
8.8KEVEPSS 0.594
CVE-2020-1300
A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files.To exploit the vulnerability, an attacker would have to convince a user to either open a specially crafted cabinet file or spoof a network printer and trick a user into installing a malicious cabinet file disguised as a printer driver.The update addresses the vulnerability by correcting how Windows handles cabinet files., aka 'Windows Remote Code Execution Vulnerability'.
Published 2020-06-09 · Modified
8.8EPSS 0.594
CVE-2014-4123
Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a different vulnerability than CVE-2014-4124.
Published 2014-10-15 · Analyzed
8.8KEVEPSS 0.471
← Prev18 / 72Next →