Microsoft Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Microsoft products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

403

In CISA KEV

383

Beyond CISA KEV

20

Sensor Observed

2

Virtual Patch Available

0

Microsoft KEVs Added by Year

Loading...

403 Microsoft KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2019-0541

A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution...

Confirmed In CISA 03 Nov 2021
CVE-2021-27085

Internet Explorer Remote Code Execution Vulnerability

Confirmed In CISA 03 Nov 2021
CVE-2015-1641

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word...

Confirmed In CISA 03 Nov 2021
CVE-2012-0158

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003...

Confirmed In CISA 03 Nov 2021
CVE-2018-0802

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution...

Confirmed In CISA 03 Nov 2021
CVE-2018-0798

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution...

Confirmed In CISA 03 Nov 2021
CVE-2019-1215

An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege...

Confirmed In CISA 03 Nov 2021
CVE-2021-36942

Windows LSA Spoofing Vulnerability

Confirmed In CISA 03 Nov 2021
CVE-2019-0797

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k...

Confirmed In CISA 03 Nov 2021
CVE-2018-8653

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting...

Confirmed In CISA 03 Nov 2021
CVE-2017-8759

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or...

Confirmed In CISA 03 Nov 2021
CVE-2021-40444

Microsoft MSHTML Remote Code Execution Vulnerability

Confirmed In CISA 03 Nov 2021
CVE-2019-0859

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k...

Confirmed In CISA 03 Nov 2021
CVE-2021-26411

Internet Explorer Memory Corruption Vulnerability

Confirmed In CISA 03 Nov 2021
CVE-2020-1350

A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS...

Confirmed In CISA 03 Nov 2021
CVE-2021-28310

Win32k Elevation of Privilege Vulnerability

Confirmed In CISA 03 Nov 2021
CVE-2020-1040

A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated...

Confirmed In CISA 03 Nov 2021
CVE-2019-0803

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k...

Confirmed In CISA 03 Nov 2021
CVE-2021-31207

Microsoft Exchange Server Security Feature Bypass Vulnerability

Confirmed In CISA 03 Nov 2021
CVE-2021-34527

Windows Print Spooler Remote Code Execution Vulnerability

Confirmed In CISA 03 Nov 2021
CVE-2021-1732

Windows Win32k Elevation of Privilege Vulnerability

Confirmed In CISA 03 Nov 2021
CVE-2020-1464

Windows Spoofing Vulnerability

Confirmed In CISA 03 Nov 2021
CVE-2021-34473

Microsoft Exchange Server Remote Code Execution Vulnerability

Confirmed In CISA 03 Nov 2021
CVE-2019-0708

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker...

Confirmed In CISA 03 Nov 2021
CVE-2016-7255

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold...

Confirmed In CISA 03 Nov 2021

Common Vulnerability Classes (CWE)

  • CWE-787 — Out-of-bounds Write 45
  • CWE-416 — Use After Free 34
  • CWE-59 — Improper Link Resolution Before File Access ('Link Following') 18
  • CWE-20 — Improper Input Validation 16
  • CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 16
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 14
  • CWE-502 — Deserialization of Untrusted Data 13
  • CWE-269 — Improper Privilege Management 9

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology