Microsoft Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Microsoft products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

403

In CISA KEV

383

Beyond CISA KEV

20

Sensor Observed

3

Virtual Patch Available

0

Microsoft KEVs Added by Year

Loading...

403 Microsoft KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2017-11826

Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word...

Confirmed In CISA 03 Mar 2022
CVE-2017-8540

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1,...

Confirmed In CISA 03 Mar 2022
CVE-2018-8298

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine...

Confirmed In CISA 03 Mar 2022
CVE-2018-8581

An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability."...

Confirmed In CISA 03 Mar 2022
CVE-2019-1297

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka...

Confirmed In CISA 03 Mar 2022
CVE-2021-41379

Windows Installer Elevation of Privilege Vulnerability

Confirmed In CISA 03 Mar 2022
CVE-2015-2546

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server...

Confirmed In CISA 15 Mar 2022
CVE-2016-3309

The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold...

Confirmed In CISA 15 Mar 2022
CVE-2017-0101

The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows...

Confirmed In CISA 15 Mar 2022
CVE-2018-8120

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k...

Confirmed In CISA 15 Mar 2022
CVE-2019-0543

An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft Windows Elevation of...

Confirmed In CISA 15 Mar 2022
CVE-2019-0841

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation...

Confirmed In CISA 15 Mar 2022
CVE-2019-1064

Windows Elevation of Privilege Vulnerability

Confirmed In CISA 15 Mar 2022
CVE-2019-1069

Task Scheduler Elevation of Privilege Vulnerability

Confirmed In CISA 15 Mar 2022
CVE-2019-1129

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation...

Confirmed In CISA 15 Mar 2022
CVE-2019-1132

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k...

Confirmed In CISA 15 Mar 2022
CVE-2019-1253

An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability,...

Confirmed In CISA 15 Mar 2022
CVE-2019-1315

An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting...

Confirmed In CISA 15 Mar 2022
CVE-2019-1322

An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of...

Confirmed In CISA 15 Mar 2022
CVE-2019-1405

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka...

Confirmed In CISA 15 Mar 2022
CVE-2014-6324

The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7...

Confirmed In CISA 25 Mar 2022
CVE-2014-6332

OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows...

Confirmed In CISA 25 Mar 2022
CVE-2017-0146

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;...

Confirmed In CISA 25 Mar 2022
CVE-2018-8373

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting...

Confirmed In CISA 25 Mar 2022
CVE-2018-8414

A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution...

Confirmed In CISA 25 Mar 2022

Common Vulnerability Classes (CWE)

  • CWE-787 — Out-of-bounds Write 45
  • CWE-416 — Use After Free 34
  • CWE-59 — Improper Link Resolution Before File Access ('Link Following') 18
  • CWE-20 — Improper Input Validation 16
  • CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 16
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 14
  • CWE-502 — Deserialization of Untrusted Data 13
  • CWE-269 — Improper Privilege Management 9

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology