Microsoft Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Microsoft products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

403

In CISA KEV

383

Beyond CISA KEV

20

Sensor Observed

2

Virtual Patch Available

0

Microsoft KEVs Added by Year

Loading...

403 Microsoft KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2019-0863

An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of...

Confirmed In CISA 03 Nov 2021
CVE-2016-3235

Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which...

Confirmed In CISA 03 Nov 2021
CVE-2019-1214

An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka...

Confirmed In CISA 03 Nov 2021
CVE-2020-1147

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source...

Confirmed In CISA 03 Nov 2021
CVE-2021-26857

Microsoft Exchange Server Remote Code Execution Vulnerability

Confirmed In CISA 03 Nov 2021
CVE-2019-0808

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k...

Confirmed In CISA 03 Nov 2021
CVE-2020-0646

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code...

Confirmed In CISA 03 Nov 2021
CVE-2019-0604

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package,...

Confirmed In CISA 03 Nov 2021
CVE-2020-0601

A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker...

Confirmed In CISA 03 Nov 2021
CVE-2021-34448

Scripting Engine Memory Corruption Vulnerability

Confirmed In CISA 03 Nov 2021
CVE-2021-1675

Windows Print Spooler Remote Code Execution Vulnerability

Confirmed In CISA 03 Nov 2021
CVE-2020-1054

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka...

Confirmed In CISA 03 Nov 2021
CVE-2021-27065

Microsoft Exchange Server Remote Code Execution Vulnerability

Confirmed In CISA 03 Nov 2021
CVE-2021-26858

Microsoft Exchange Server Remote Code Execution Vulnerability

Confirmed In CISA 03 Nov 2021
CVE-2021-26855

Microsoft Exchange Server Remote Code Execution Vulnerability

Confirmed In CISA 03 Nov 2021
CVE-2020-1472

Netlogon Elevation of Privilege Vulnerability

Confirmed In CISA 03 Nov 2021
CVE-2020-0968

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting...

Confirmed In CISA 03 Nov 2021
CVE-2017-11774

Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft...

Confirmed In CISA 03 Nov 2021
CVE-2019-1429

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting...

Confirmed In CISA 03 Nov 2021
CVE-2020-1380

Scripting Engine Memory Corruption Vulnerability

Confirmed In CISA 03 Nov 2021
CVE-2017-0199

Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server...

Confirmed In CISA 03 Nov 2021
CVE-2019-1367

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting...

Confirmed In CISA 03 Nov 2021
CVE-2021-27059

Microsoft Office Remote Code Execution Vulnerability

Confirmed In CISA 03 Nov 2021
CVE-2020-0674

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting...

Confirmed In CISA 03 Nov 2021
CVE-2017-11882

Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow...

Confirmed In CISA 03 Nov 2021

Common Vulnerability Classes (CWE)

  • CWE-787 — Out-of-bounds Write 45
  • CWE-416 — Use After Free 34
  • CWE-59 — Improper Link Resolution Before File Access ('Link Following') 18
  • CWE-20 — Improper Input Validation 16
  • CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 16
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 14
  • CWE-502 — Deserialization of Untrusted Data 13
  • CWE-269 — Improper Privilege Management 9

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology