Microsoft Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Microsoft products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
403
In CISA KEV
383
Beyond CISA KEV
20
Sensor Observed
3
Virtual Patch Available
0
Microsoft KEVs Added by Year
403 Microsoft KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2014-6352
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and... |
Windows | Confirmed | In CISA | 25 Feb 2022 |
|
CVE-2017-0222
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption... |
Internet Explorer | Confirmed | In CISA | 25 Feb 2022 |
|
CVE-2017-8570
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code... |
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, and Microsoft Office 2016. | Confirmed | In CISA | 25 Feb 2022 |
|
CVE-2002-0367
smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows... |
Windows | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2004-0210
The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by... |
Windows NT, Windows 2000 | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2009-1123
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate... |
Windows | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2009-3129
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel... |
Office Excel | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2010-0232
The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows... |
Windows | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2010-3333
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac... |
Office | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2011-1889
The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute... |
Forefront Threat Management Gateway 2010 | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2012-1856
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2... |
Office | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2013-1347
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an... |
Internet Explorer 8 | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2013-3897
Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to... |
Internet Explorer | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2013-5065
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application,... |
Windows | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2014-4114
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and... |
Windows | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2015-1642
Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office... |
Office | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2015-1701
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges... |
Windows | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2015-2387
ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,... |
Windows | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2015-2424
Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1... |
Office | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2015-2545
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka... |
Office | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2016-0099
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012... |
Windows | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2016-7193
Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility... |
Word | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2016-7262
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow... |
Excel | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-0001
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server... |
Windows GDI | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-0261
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle... |
Microsoft Office | Confirmed | In CISA | 03 Mar 2022 |
Common Vulnerability Classes (CWE)
- CWE-787 — Out-of-bounds Write 45
- CWE-416 — Use After Free 34
- CWE-59 — Improper Link Resolution Before File Access ('Link Following') 18
- CWE-20 — Improper Input Validation 16
- CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 16
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 14
- CWE-502 — Deserialization of Untrusted Data 13
- CWE-269 — Improper Privilege Management 9
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology