Microsoft Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Microsoft products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

403

In CISA KEV

383

Beyond CISA KEV

20

Sensor Observed

3

Virtual Patch Available

0

Microsoft KEVs Added by Year

Loading...

403 Microsoft KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2021-31166

HTTP Protocol Stack Remote Code Execution Vulnerability

Confirmed In CISA 06 Apr 2022
CVE-2021-42278

Active Directory Domain Services Elevation of Privilege Vulnerability

Confirmed In CISA 11 Apr 2022
CVE-2021-42287

Active Directory Domain Services Elevation of Privilege Vulnerability

Confirmed In CISA 11 Apr 2022
CVE-2015-2502

Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a...

Confirmed In CISA 13 Apr 2022
CVE-2022-24521

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Confirmed In CISA 13 Apr 2022
CVE-2022-22718

Windows Print Spooler Elevation of Privilege Vulnerability

Confirmed In CISA 19 Apr 2022
CVE-2021-40450

Win32k Elevation of Privilege Vulnerability

Confirmed In CISA 25 Apr 2022
CVE-2021-41357

Win32k Elevation of Privilege Vulnerability

Confirmed In CISA 25 Apr 2022
CVE-2022-21919

Windows User Profile Service Elevation of Privilege Vulnerability

Confirmed In CISA 25 Apr 2022
CVE-2022-26904

Windows User Profile Service Elevation of Privilege Vulnerability

Confirmed In CISA 25 Apr 2022
CVE-2014-0322

Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving...

Confirmed In CISA 04 May 2022
CVE-2014-4113

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1,...

Confirmed In CISA 04 May 2022
CVE-2018-8589

An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k Elevation of Privilege...

Confirmed In CISA 23 May 2022
CVE-2019-1130

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation...

Confirmed In CISA 23 May 2022
CVE-2019-1385

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in...

Confirmed In CISA 23 May 2022
CVE-2019-0880

A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege...

Confirmed In CISA 23 May 2022
CVE-2019-0703

An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information...

Confirmed In CISA 23 May 2022
CVE-2019-0676

An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited...

Confirmed In CISA 23 May 2022
CVE-2020-0638

An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker...

Confirmed In CISA 23 May 2022
CVE-2020-1027

An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of...

Confirmed In CISA 23 May 2022
CVE-2016-3298

Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1...

Confirmed In CISA 24 May 2022
CVE-2016-3351

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka...

Confirmed In CISA 24 May 2022
CVE-2016-0162

Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet...

Confirmed In CISA 24 May 2022
CVE-2017-8543

Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8,...

Confirmed In CISA 24 May 2022
CVE-2017-0210

An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an...

Confirmed In CISA 24 May 2022

Common Vulnerability Classes (CWE)

  • CWE-787 — Out-of-bounds Write 45
  • CWE-416 — Use After Free 34
  • CWE-59 — Improper Link Resolution Before File Access ('Link Following') 18
  • CWE-20 — Improper Input Validation 16
  • CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 16
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 14
  • CWE-502 — Deserialization of Untrusted Data 13
  • CWE-269 — Improper Privilege Management 9

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology