Microsoft Corporation Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Microsoft Corporation products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

30

In CISA KEV

30

Beyond CISA KEV

0

Sensor Observed

0

Virtual Patch Available

0

Microsoft Corporation KEVs Added by Year

Loading...

30 Microsoft Corporation KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2017-0210

An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an...

Confirmed In CISA 24 May 2022
CVE-2017-0149

Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a...

Confirmed In CISA 24 May 2022
CVE-2017-0005

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server...

Confirmed In CISA 24 May 2022
CVE-2017-0022

Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2...

Confirmed In CISA 24 May 2022
CVE-2017-0147

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;...

Confirmed In CISA 24 May 2022

Common Vulnerability Classes (CWE)

  • CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 5
  • CWE-787 — Out-of-bounds Write 5
  • CWE-416 — Use After Free 2
  • CWE-281 — Improper Preservation of Permissions 1
  • CWE-20 — Improper Input Validation 1
  • CWE-843 — Access of Resource Using Incompatible Type ('Type Confusion') 1
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology