VendorsMicrosoftwindows_8.1all versions
Vulnerabilities

Microsoft Windows 8.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2873CVEs
CVE-2022-21963
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
7.2EPSS 0.007
CVE-2016-0120
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to cause a denial of service (system hang) via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability."
Published 2016-03-09 · Modified
7.11 PoCEPSS 0.367
CVE-2017-0016
Microsoft Windows 10 Gold, 1511, and 1607; Windows 8.1; Windows RT 8.1; Windows Server 2012 R2, and Windows Server 2016 do not properly handle certain requests in SMBv2 and SMBv3 packets, which allows remote attackers to execute arbitrary code via a crafted SMBv2 or SMBv3 packet to the Server service, aka "SMBv2/SMBv3 Null Dereference Denial of Service Vulnerability."
Published 2017-03-17 · Modified
7.1EPSS 0.257
CVE-2014-0266
The XMLHTTP ActiveX controls in XML Core Services 3.0 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to bypass the Same Origin Policy via a web page that is visited in Internet Explorer, aka "MSXML Information Disclosure Vulnerability."
Published 2014-02-12 · Modified
7.1EPSS 0.194
CVE-2014-6317
Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to cause a denial of service (reboot) via a crafted TrueType font, aka "Denial of Service in Windows Kernel Mode Driver Vulnerability."
Published 2014-11-11 · Modified
7.1EPSS 0.184
CVE-2019-1347
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1343, CVE-2019-1346.
Published 2019-10-10 · Modified
7.11 PoCEPSS 0.149
CVE-2018-8304
A denial of service vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, aka "Windows DNSAPI Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-07-11 · Modified
7.1EPSS 0.126
CVE-2019-1343
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1346, CVE-2019-1347.
Published 2019-10-10 · Modified
7.11 PoCEPSS 0.109
CVE-2019-1346
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1343, CVE-2019-1347.
Published 2019-10-10 · Modified
7.11 PoCEPSS 0.109
CVE-2018-0753
Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow a denial of service vulnerability due to the way objects are handled in memory, aka "Windows IPSec Denial of Service Vulnerability".
Published 2018-01-04 · Modified
7.1EPSS 0.090
CVE-2017-0280
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0269 and CVE-2017-0273.
Published 2017-05-12 · Modified
7.1EPSS 0.072
CVE-2019-1238
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1239.
Published 2019-10-10 · Modified
7.1EPSS 0.059
CVE-2013-3876
DirectAccess in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly verify server X.509 certificates, which allows man-in-the-middle attackers to spoof servers and read encrypted domain credentials via a crafted certificate.
Published 2013-11-16 · Modified
7.1EPSS 0.052
CVE-2022-30155
Windows Kernel Denial of Service Vulnerability
Published 2022-06-15 · Modified
7.1EPSS 0.050
CVE-2016-0089
Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to obtain sensitive information from host OS memory via a crafted application, aka "Hyper-V Information Disclosure Vulnerability."
Published 2016-04-12 · Modified
7.1EPSS 0.034
CVE-2016-0090
Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 allows guest OS users to obtain sensitive information from host OS memory via a crafted application, aka "Hyper-V Information Disclosure Vulnerability."
Published 2016-04-12 · Modified
7.1EPSS 0.030
CVE-2018-0751
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way the Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2018-0752.
Published 2018-01-04 · Modified
7.11 PoCEPSS 0.028
CVE-2019-0986
Windows User Profile Service Elevation of Privilege Vulnerability
Published 2019-06-12 · Modified
7.1EPSS 0.021
CVE-2022-38042
Active Directory Domain Services Elevation of Privilege Vulnerability
Published 2022-10-11 · Modified
7.1EPSS 0.014
CVE-2020-0730
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.
Published 2020-02-11 · Modified
7.1EPSS 0.009
CVE-2019-1161
Microsoft Defender Elevation of Privilege Vulnerability
Published 2019-08-14 · Modified
7.1EPSS 0.009
CVE-2021-31182
Microsoft Bluetooth Driver Spoofing Vulnerability
Published 2021-05-11 · Modified
7.1EPSS 0.008
CVE-2022-21997
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2022-02-09 · Modified
7.1EPSS 0.008
CVE-2020-0936
An elevation of privilege vulnerability exists when a Windows scheduled task improperly handles file redirections, aka 'Windows Scheduled Task Elevation of Privilege Vulnerability'.
Published 2020-04-15 · Modified
7.1EPSS 0.008
CVE-2022-22022
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2022-07-12 · Modified
7.1EPSS 0.008
CVE-2022-30226
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2022-07-12 · Modified
7.1EPSS 0.008
CVE-2021-28446
Windows Portmapping Information Disclosure Vulnerability
Published 2021-04-13 · Modified
7.1EPSS 0.008
CVE-2020-1461
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.
Published 2020-07-14 · Modified
7.1EPSS 0.007
CVE-2020-0785
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.
Published 2020-03-12 · Modified
7.1EPSS 0.007
CVE-2023-21750
Windows Kernel Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.1EPSS 0.007
CVE-2020-1002
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.
Published 2020-04-15 · Modified
7.1EPSS 0.007
CVE-2022-34690
Windows Fax Service Elevation of Privilege Vulnerability
Published 2022-08-09 · Modified
7.1EPSS 0.006
CVE-2022-30225
Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability
Published 2022-07-12 · Modified
7.1EPSS 0.006
CVE-2023-21760
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.1EPSS 0.005
CVE-2022-26904
Windows User Profile Service Elevation of Privilege Vulnerability
Published 2022-04-15 · Analyzed
7.0KEVEPSS 0.169
CVE-2018-0744
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Elevation of Privilege Vulnerability".
Published 2018-01-04 · Modified
7.01 PoCEPSS 0.150
CVE-2017-0277
The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0272, CVE-2017-0278, and CVE-2017-0279.
Published 2017-05-12 · Modified
7.0EPSS 0.109
CVE-2017-0278
The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0272, CVE-2017-0277, and CVE-2017-0279.
Published 2017-05-12 · Modified
7.0EPSS 0.109
CVE-2017-0279
The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0272, CVE-2017-0277, and CVE-2017-0278.
Published 2017-05-12 · Modified
7.0EPSS 0.109
CVE-2017-11780
The Server Message Block 1.0 (SMBv1) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows a remote code execution vulnerability when it fails to properly handle certain requests, aka "Windows SMB Remote Code Execution Vulnerability".
Published 2017-10-13 · Modified
7.0EPSS 0.100
← Prev52 / 72Next →