Microsoft Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Microsoft products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
403
In CISA KEV
383
Beyond CISA KEV
20
Sensor Observed
3
Virtual Patch Available
0
Microsoft KEVs Added by Year
403 Microsoft KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2017-0149
Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a... |
Internet Explorer | Confirmed | In CISA | 24 May 2022 |
|
CVE-2017-0005
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server... |
Windows GDI | Confirmed | In CISA | 24 May 2022 |
|
CVE-2017-0022
Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2... |
XML Core Services | Confirmed | In CISA | 24 May 2022 |
|
CVE-2017-0147
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;... |
Windows SMB | Confirmed | In CISA | 24 May 2022 |
|
CVE-2018-8611
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of... |
Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers | Confirmed | In CISA | 24 May 2022 |
|
CVE-2013-0074
Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows... |
Silverlight | Confirmed | In CISA | 25 May 2022 |
|
CVE-2013-3896
Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, which allows remote attackers... |
Silverlight | Confirmed | In CISA | 25 May 2022 |
|
CVE-2013-7331
The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames,... |
Windows | Confirmed | In CISA | 25 May 2022 |
|
CVE-2014-4077
Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka... |
Windows | Confirmed | In CISA | 25 May 2022 |
|
CVE-2014-2817
Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of... |
Internet Explorer | Confirmed | In CISA | 25 May 2022 |
|
CVE-2014-4123
Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of... |
Internet Explorer | Confirmed | In CISA | 25 May 2022 |
|
CVE-2014-4148
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1,... |
Windows | Confirmed | In CISA | 25 May 2022 |
|
CVE-2015-1671
The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2;... |
Windows DirectWrite | Confirmed | In CISA | 25 May 2022 |
|
CVE-2015-6175
The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of... |
Windows 10 | Confirmed | In CISA | 25 May 2022 |
|
CVE-2015-1769
Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold... |
Windows | Confirmed | In CISA | 25 May 2022 |
|
CVE-2015-2425
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web... |
Internet Explorer | Confirmed | In CISA | 25 May 2022 |
|
CVE-2015-2360
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,... |
Windows | Confirmed | In CISA | 25 May 2022 |
|
CVE-2015-0071
Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet... |
Internet Explorer | Confirmed | In CISA | 25 May 2022 |
|
CVE-2015-0016
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2... |
Windows | Confirmed | In CISA | 25 May 2022 |
|
CVE-2016-0034
Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or... |
Silverlight | Confirmed | In CISA | 25 May 2022 |
|
CVE-2016-7256
atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows... |
Windows | Confirmed | In CISA | 25 May 2022 |
|
CVE-2016-3393
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows... |
Windows | Confirmed | In CISA | 25 May 2022 |
|
CVE-2006-2492
Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows... |
Word | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2009-0557
Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and... |
Office | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2009-0563
Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML... |
Office | Confirmed | In CISA | 08 Jun 2022 |
Common Vulnerability Classes (CWE)
- CWE-787 — Out-of-bounds Write 45
- CWE-416 — Use After Free 34
- CWE-59 — Improper Link Resolution Before File Access ('Link Following') 18
- CWE-20 — Improper Input Validation 16
- CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 16
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 14
- CWE-502 — Deserialization of Untrusted Data 13
- CWE-269 — Improper Privilege Management 9
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology