VendorsMicrosoftwindows_8.1all versions
Vulnerabilities

Microsoft Windows 8.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2873CVEs
CVE-2022-41095
Windows Digital Media Receiver Elevation of Privilege Vulnerability
Published 2022-11-09 · Modified
7.8EPSS 0.005
CVE-2022-41094
Windows Hyper-V Elevation of Privilege Vulnerability
Published 2022-12-13 · Modified
7.8EPSS 0.005
CVE-2022-37986
Windows Win32k Elevation of Privilege Vulnerability
Published 2022-10-11 · Modified
7.8EPSS 0.005
CVE-2022-44680
Windows Graphics Component Elevation of Privilege Vulnerability
Published 2022-12-13 · Modified
7.8EPSS 0.005
CVE-2023-21755
Windows Kernel Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.8EPSS 0.005
CVE-2022-37984
Windows WLAN Service Elevation of Privilege Vulnerability
Published 2022-10-11 · Modified
7.8EPSS 0.005
CVE-2021-41370
NTFS Elevation of Privilege Vulnerability
Published 2021-11-10 · Modified
7.8EPSS 0.005
CVE-2021-41367
NTFS Elevation of Privilege Vulnerability
Published 2021-11-10 · Modified
7.8EPSS 0.005
CVE-2021-41377
Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
Published 2021-11-10 · Modified
7.8EPSS 0.005
CVE-2021-41366
Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
Published 2021-11-10 · Modified
7.8EPSS 0.005
CVE-2023-21726
Windows Credential Manager User Interface Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.8EPSS 0.005
CVE-2023-21680
Windows Win32k Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.8EPSS 0.005
CVE-2023-21765
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.8EPSS 0.005
CVE-2023-21754
Windows Kernel Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.8EPSS 0.005
CVE-2023-21558
Windows Error Reporting Service Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.8EPSS 0.005
CVE-2023-21767
Windows Overlay Filter Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.8EPSS 0.005
CVE-2022-34706
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
Published 2022-08-09 · Modified
7.8EPSS 0.004
CVE-2023-21561
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.8EPSS 0.004
CVE-2022-22008
Windows Hyper-V Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
7.8EPSS 0.004
CVE-2023-21524
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.8EPSS 0.004
CVE-2018-16098
In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user.
Published 2019-01-24 · Modified
7.8EPSS 0.004
CVE-2017-3762
Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a hard-coded password, and is accessible to all users with local non-administrative access to the system in which it is installed.
Published 2018-01-26 · Modified
7.8EPSS 0.004
CVE-2017-3756
A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path.
Published 2017-08-18 · Modified
7.8EPSS 0.004
CVE-2022-34696
Windows Hyper-V Remote Code Execution Vulnerability
Published 2022-08-09 · Modified
7.8EPSS 0.003
CVE-2018-16160
SecureCore Standard Edition Version 2.x allows an attacker to bypass the product 's authentication to log in to a Windows PC.
Published 2018-11-15 · Modified
7.8EPSS 0.003
CVE-2022-41100
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Published 2022-11-09 · Modified
7.8EPSS 0.003
CVE-2022-41045
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Published 2022-11-09 · Modified
7.8EPSS 0.003
CVE-2022-41093
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Published 2022-11-09 · Modified
7.8EPSS 0.003
CVE-2020-0559
Insecure inherited permissions in some Intel(R) PROSet/Wireless WiFi products on Windows* 7 and 8.1 before version 21.40.5.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
Published 2020-08-13 · Modified
7.8EPSS 0.003
CVE-2021-30605
Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls.
Published 2021-09-08 · Modified
7.8EPSS 0.001
CVE-2020-16997
Remote Desktop Protocol Server Information Disclosure Vulnerability
Published 2020-11-11 · Modified
7.7EPSS 0.040
CVE-2021-1692
Windows Hyper-V Denial of Service Vulnerability
Published 2021-01-12 · Modified
7.7EPSS 0.039
CVE-2021-34500
Windows Kernel Memory Information Disclosure Vulnerability
Published 2021-07-14 · Modified
7.7EPSS 0.026
CVE-2021-40463
Windows Network Address Translation (NAT) Denial of Service Vulnerability
Published 2021-10-13 · Modified
7.7EPSS 0.026
CVE-2016-0189
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.
Published 2016-05-11 · Analyzed
7.6KEV1 PoCEPSS 0.941
CVE-2018-8174
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-05-09 · Analyzed
7.6KEV1 PoCEPSS 0.883
CVE-2020-0674
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.
Published 2020-02-11 · Analyzed
7.6KEV2 PoCEPSS 0.869
CVE-2018-0886
The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709 Windows Server 2016 and Windows Server, version 1709 allows a remote code execution vulnerability due to how CredSSP validates request during the authentication process, aka "CredSSP Remote Code Execution Vulnerability".
Published 2018-03-14 · Modified
7.61 PoCEPSS 0.820
CVE-2019-0752
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0739, CVE-2019-0753, CVE-2019-0862.
Published 2019-04-09 · Analyzed
7.6KEV1 PoCEPSS 0.816
CVE-2019-1429
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1428.
Published 2019-11-12 · Analyzed
7.6KEV1 PoCEPSS 0.773
← Prev42 / 72Next →