Microsoft Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Microsoft products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
403
In CISA KEV
383
Beyond CISA KEV
20
Sensor Observed
3
Virtual Patch Available
0
Microsoft KEVs Added by Year
403 Microsoft KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2017-11826
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word... |
Microsoft Office | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-8540
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1,... |
Malware Protection Engine | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-8298
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine... |
ChakraCore | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-8581
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability."... |
Microsoft Exchange Server | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2019-1297
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka... |
Microsoft Excel, Microsoft Office, Office 365 ProPlus | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2021-41379
Windows Installer Elevation of Privilege Vulnerability |
Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2015-2546
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server... |
Windows | Confirmed | In CISA | 15 Mar 2022 |
|
CVE-2016-3309
The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold... |
Windows | Confirmed | In CISA | 15 Mar 2022 |
|
CVE-2017-0101
The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows... |
Windows | Confirmed | In CISA | 15 Mar 2022 |
|
CVE-2018-8120
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k... |
Windows Server 2008, Windows 7, Windows Server 2008 R2 | Confirmed | In CISA | 15 Mar 2022 |
|
CVE-2019-0543
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft Windows Elevation of... |
Windows | Confirmed | In CISA | 15 Mar 2022 |
|
CVE-2019-0841
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation... |
Windows, Windows Server | Confirmed | In CISA | 15 Mar 2022 |
|
CVE-2019-1064
Windows Elevation of Privilege Vulnerability |
Windows 10 Version 1703, Windows 10 Version 1803, Windows Server, version 1803 (Server Core Installation), Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1709 for 32-bit Systems, Windows 10 Version 1709, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation) | Confirmed | In CISA | 15 Mar 2022 |
|
CVE-2019-1069
Task Scheduler Elevation of Privilege Vulnerability |
Windows 10 Version 1703, Windows 10 Version 1803, Windows Server, version 1803 (Server Core Installation), Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1709 for 32-bit Systems, Windows 10 Version 1709, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation) | Confirmed | In CISA | 15 Mar 2022 |
|
CVE-2019-1129
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation... |
Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | Confirmed | In CISA | 15 Mar 2022 |
|
CVE-2019-1132
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k... |
Windows, Windows Server | Confirmed | In CISA | 15 Mar 2022 |
|
CVE-2019-1253
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability,... |
Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | Confirmed | In CISA | 15 Mar 2022 |
|
CVE-2019-1315
An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting... |
Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | Confirmed | In CISA | 15 Mar 2022 |
|
CVE-2019-1322
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of... |
Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | Confirmed | In CISA | 15 Mar 2022 |
|
CVE-2019-1405
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka... |
Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | Confirmed | In CISA | 15 Mar 2022 |
|
CVE-2014-6324
The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7... |
Windows | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2014-6332
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows... |
Windows | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2017-0146
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;... |
Windows SMB | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2018-8373
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting... |
Internet Explorer 9, Internet Explorer 11, Internet Explorer 10 | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2018-8414
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution... |
Windows 10 Servers, Windows 10 | Confirmed | In CISA | 25 Mar 2022 |
Common Vulnerability Classes (CWE)
- CWE-787 — Out-of-bounds Write 45
- CWE-416 — Use After Free 34
- CWE-59 — Improper Link Resolution Before File Access ('Link Following') 18
- CWE-20 — Improper Input Validation 16
- CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 16
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 14
- CWE-502 — Deserialization of Untrusted Data 13
- CWE-269 — Improper Privilege Management 9
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology