Microsoft Corporation Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Microsoft Corporation products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
30
In CISA KEV
30
Beyond CISA KEV
0
Sensor Observed
0
Virtual Patch Available
0
Microsoft Corporation KEVs Added by Year
30 Microsoft Corporation KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2017-0210
An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an... |
Internet Explorer | Confirmed | In CISA | 24 May 2022 |
|
CVE-2017-0149
Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a... |
Internet Explorer | Confirmed | In CISA | 24 May 2022 |
|
CVE-2017-0005
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server... |
Windows GDI | Confirmed | In CISA | 24 May 2022 |
|
CVE-2017-0022
Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2... |
XML Core Services | Confirmed | In CISA | 24 May 2022 |
|
CVE-2017-0147
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;... |
Windows SMB | Confirmed | In CISA | 24 May 2022 |
Common Vulnerability Classes (CWE)
- CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 5
- CWE-787 — Out-of-bounds Write 5
- CWE-416 — Use After Free 2
- CWE-281 — Improper Preservation of Permissions 1
- CWE-20 — Improper Input Validation 1
- CWE-843 — Access of Resource Using Incompatible Type ('Type Confusion') 1
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology