Microsoft Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Microsoft products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
403
In CISA KEV
383
Beyond CISA KEV
20
Sensor Observed
3
Virtual Patch Available
0
Microsoft KEVs Added by Year
403 Microsoft KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2021-38647
Open Management Infrastructure Remote Code Execution Vulnerability |
Open Management Infrastructure, System Center Operations Manager (SCOM), Azure Automation State Configuration, DSC Extension, Azure Automation Update Management, Log Analytics Agent, Azure Diagnostics (LAD), Container Monitoring Solution, Azure Security Center, Azure Sentinel, Azure Stack Hub | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2014-1812
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and... |
Windows | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-42292
Microsoft Excel Security Feature Bypass Vulnerability |
Microsoft Office 2019, Microsoft Office 2019 for Mac, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Excel 2013 Service Pack 1, Microsoft Office 2013 Service Pack 1 | Confirmed | In CISA | 17 Nov 2021 |
|
CVE-2021-42321
Microsoft Exchange Server Remote Code Execution Vulnerability |
Microsoft Exchange Server 2016 Cumulative Update 21, Microsoft Exchange Server 2019 Cumulative Update 10, Microsoft Exchange Server 2016 Cumulative Update 22, Microsoft Exchange Server 2019 Cumulative Update 11 | Confirmed | In CISA | 17 Nov 2021 |
|
CVE-2021-40449
Win32k Elevation of Privilege Vulnerability |
Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | Confirmed | In CISA | 17 Nov 2021 |
|
CVE-2021-43890
Windows AppX Installer Spoofing Vulnerability |
App Installer | Confirmed | In CISA | 15 Dec 2021 |
|
CVE-2013-3900
WinVerifyTrust Signature Validation Vulnerability |
Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 24H2, Windows Server 2025, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | Confirmed | In CISA | 10 Jan 2022 |
|
CVE-2019-1458
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k... |
Windows, Windows Server | Confirmed | In CISA | 10 Jan 2022 |
|
CVE-2021-33766
Microsoft Exchange Server Information Disclosure Vulnerability |
Microsoft Exchange Server 2019 Cumulative Update 9, Microsoft Exchange Server 2016 Cumulative Update 20, Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2019 Cumulative Update 8 | Confirmed | In CISA | 18 Jan 2022 |
|
CVE-2018-8453
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k... |
Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers | Confirmed | In CISA | 21 Jan 2022 |
|
CVE-2014-1776
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of... |
Internet Explorer | Confirmed | In CISA | 28 Jan 2022 |
|
CVE-2020-0787
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links,... |
Windows, Windows Server, Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | Confirmed | In CISA | 28 Jan 2022 |
|
CVE-2022-21882
Win32k Elevation of Privilege Vulnerability |
Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2 | Confirmed | In CISA | 04 Feb 2022 |
|
CVE-2015-1635
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote... |
Windows | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2017-0144
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;... |
Windows SMB | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2017-0145
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;... |
Windows SMB | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2017-0262
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle... |
Microsoft Office | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2017-0263
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT... |
Microsoft Windows | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2017-8464
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT... |
Windows Shell | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2020-0796
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests,... |
Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation) | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2021-36934
Windows Elevation of Privilege Vulnerability |
Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows 10 Version 20H2 | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2013-3906
GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync... |
Windows, Office, Office Compatibility Pack, Lync | Confirmed | In CISA | 15 Feb 2022 |
|
CVE-2014-1761
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word... |
Word | Confirmed | In CISA | 15 Feb 2022 |
|
CVE-2018-8174
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote... |
Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers | Confirmed | In CISA | 15 Feb 2022 |
|
CVE-2019-0752
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting... |
Internet Explorer 11, Internet Explorer 10 | Confirmed | In CISA | 15 Feb 2022 |
Common Vulnerability Classes (CWE)
- CWE-787 — Out-of-bounds Write 45
- CWE-416 — Use After Free 34
- CWE-59 — Improper Link Resolution Before File Access ('Link Following') 18
- CWE-20 — Improper Input Validation 16
- CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 16
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 14
- CWE-502 — Deserialization of Untrusted Data 13
- CWE-269 — Improper Privilege Management 9
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology