Microsoft Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Microsoft products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

403

In CISA KEV

383

Beyond CISA KEV

20

Sensor Observed

2

Virtual Patch Available

0

Microsoft KEVs Added by Year

Loading...

403 Microsoft KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2025-62221

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Confirmed In CISA 01 Jun 2026
CVE-2025-62215

Windows Kernel Elevation of Privilege Vulnerability

Confirmed In CISA 01 Jun 2026
CVE-2025-59287

Windows Server Update Service (WSUS) Remote Code Execution Vulnerability

Confirmed In CISA 01 Jun 2026
CVE-2025-33073

Windows SMB Client Elevation of Privilege Vulnerability

Confirmed In CISA 01 Jun 2026
CVE-2025-59230

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

Confirmed In CISA 01 Jun 2026
CVE-2025-24990

Windows Agere Modem Driver Elevation of Privilege Vulnerability

Confirmed In CISA 01 Jun 2026
CVE-2021-43226

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Confirmed In CISA 01 Jun 2026
CVE-2013-3893

Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote...

Confirmed In CISA 01 Jun 2026
CVE-2007-0671

Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted...

Confirmed In CISA 01 Jun 2026
CVE-2025-49706

Microsoft SharePoint Server Spoofing Vulnerability

Confirmed In CISA 01 Jun 2026
CVE-2025-49704

Microsoft SharePoint Remote Code Execution Vulnerability

Confirmed In CISA 01 Jun 2026
CVE-2025-53770

Microsoft SharePoint Server Remote Code Execution Vulnerability

Confirmed In CISA 01 Jun 2026
CVE-2025-33053

Internet Shortcut Files Remote Code Execution Vulnerability

Confirmed In CISA 01 Jun 2026
CVE-2025-32709

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Confirmed In CISA 21 May 2025
CVE-2025-32706

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Confirmed In CISA 21 May 2025
CVE-2025-32701

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Confirmed In CISA 21 May 2025
CVE-2025-30400

Microsoft DWM Core Library Elevation of Privilege Vulnerability

Confirmed In CISA 21 May 2025
CVE-2025-30397

Scripting Engine Memory Corruption Vulnerability

Confirmed In CISA 21 May 2025
CVE-2023-24932

Secure Boot Security Feature Bypass Vulnerability

High Not in CISA 09 May 2023
CVE-2022-21894

Secure Boot Security Feature Bypass Vulnerability

High Not in CISA 11 Jan 2022
CVE-2014-1809

The MSCOMCTL library in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013 Gold, SP1, RT, and RT SP1 makes it easier for remote attackers to...

High Not in CISA 14 May 2014
CVE-2014-1807

The ShellExecute API in Windows Shell in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1,...

High Not in CISA 14 May 2014
CVE-2014-0295

VsaVb7rt.dll in Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not implement the ASLR protection mechanism, which makes it easier for remote...

High Not in CISA 12 Feb 2014
CVE-2014-0253

Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine TCP connection states, which allows remote...

High Not in CISA 12 Feb 2014
CVE-2013-5057

hxds.dll in Microsoft Office 2007 SP3 and 2010 SP1 and SP2 does not implement the ASLR protection mechanism, which makes it easier for remote...

High Not in CISA 11 Dec 2013

Common Vulnerability Classes (CWE)

  • CWE-787 — Out-of-bounds Write 45
  • CWE-416 — Use After Free 34
  • CWE-59 — Improper Link Resolution Before File Access ('Link Following') 18
  • CWE-20 — Improper Input Validation 16
  • CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 16
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 14
  • CWE-502 — Deserialization of Untrusted Data 13
  • CWE-269 — Improper Privilege Management 9

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology