Microsoft Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Microsoft products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

403

In CISA KEV

383

Beyond CISA KEV

20

Sensor Observed

3

Virtual Patch Available

0

Microsoft KEVs Added by Year

Loading...

403 Microsoft KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2021-38647

Open Management Infrastructure Remote Code Execution Vulnerability

Confirmed In CISA 03 Nov 2021
CVE-2014-1812

The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and...

Confirmed In CISA 03 Nov 2021
CVE-2021-42292

Microsoft Excel Security Feature Bypass Vulnerability

Confirmed In CISA 17 Nov 2021
CVE-2021-42321

Microsoft Exchange Server Remote Code Execution Vulnerability

Confirmed In CISA 17 Nov 2021
CVE-2021-40449

Win32k Elevation of Privilege Vulnerability

Confirmed In CISA 17 Nov 2021
CVE-2021-43890

Windows AppX Installer Spoofing Vulnerability

Confirmed In CISA 15 Dec 2021
CVE-2013-3900

WinVerifyTrust Signature Validation Vulnerability

Confirmed In CISA 10 Jan 2022
CVE-2019-1458

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k...

Confirmed In CISA 10 Jan 2022
CVE-2021-33766

Microsoft Exchange Server Information Disclosure Vulnerability

Confirmed In CISA 18 Jan 2022
CVE-2018-8453

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k...

Confirmed In CISA 21 Jan 2022
CVE-2014-1776

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of...

Confirmed In CISA 28 Jan 2022
CVE-2020-0787

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links,...

Confirmed In CISA 28 Jan 2022
CVE-2022-21882

Win32k Elevation of Privilege Vulnerability

Confirmed In CISA 04 Feb 2022
CVE-2015-1635

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote...

Confirmed In CISA 10 Feb 2022
CVE-2017-0144

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;...

Confirmed In CISA 10 Feb 2022
CVE-2017-0145

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;...

Confirmed In CISA 10 Feb 2022
CVE-2017-0262

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle...

Confirmed In CISA 10 Feb 2022
CVE-2017-0263

The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT...

Confirmed In CISA 10 Feb 2022
CVE-2017-8464

Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT...

Confirmed In CISA 10 Feb 2022
CVE-2020-0796

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests,...

Confirmed In CISA 10 Feb 2022
CVE-2021-36934

Windows Elevation of Privilege Vulnerability

Confirmed In CISA 10 Feb 2022
CVE-2013-3906

GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync...

Confirmed In CISA 15 Feb 2022
CVE-2014-1761

Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word...

Confirmed In CISA 15 Feb 2022
CVE-2018-8174

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote...

Confirmed In CISA 15 Feb 2022
CVE-2019-0752

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting...

Confirmed In CISA 15 Feb 2022

Common Vulnerability Classes (CWE)

  • CWE-787 — Out-of-bounds Write 45
  • CWE-416 — Use After Free 34
  • CWE-59 — Improper Link Resolution Before File Access ('Link Following') 18
  • CWE-20 — Improper Input Validation 16
  • CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 16
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 14
  • CWE-502 — Deserialization of Untrusted Data 13
  • CWE-269 — Improper Privilege Management 9

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology