About “Microsoft Windows”

A curated feed of “Microsoft Windows”-related CVEs appears below. We currently track 14516 CVEs for this tag (all time). In the last 365 days, 1677 were published. Average CVSS is 7.3 (all time; 7.2 over 365d), and 66% are rated High/Critical (all time). Top CWEs (last 365 days): CWE-416 - Use After Free, CWE-122 - Heap-based Buffer Overflow, CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition').

In our taxonomy this topic maps to a MODERATE impact class. Issues here typically affect operating system packages or kernels. Plan reboots or service restarts and coordinate rollouts across fleets. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.

CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).

CVSS ≥ 0.0
2022-11-11
Medium

CVE-2022-36380

Uncontrolled search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalat…

Medium

CVE-2022-36377

Insecure inherited permissions in some Intel(R) Wireless Adapter Driver installation software for Intel(R) NUC Kits & Mini PCs before version 22.190.0.3 for Windows may allow an authenticated user to…

Low

CVE-2022-33973

Improper access control in the Intel(R) WAPI Security software for Windows 10/11 before version 22.2150.0.1 may allow an authenticated user to potentially enable information disclosure via local acce…

2022-11-10
Low

CVE-2022-41874

Tauri is a framework for building binaries for all major desktop platforms. In versions prior to 1.0.7 and 1.1.2, Tauri is vulnerable to an Incorrectly-Resolved Name. Due to incorrect escaping of spe…

Medium

CVE-2022-34666

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a local user with basic capabilities can cause a null-pointer dereference, which may lead to d…

2022-11-09
High

CVE-2022-41128

Windows Scripting Languages Remote Code Execution Vulnerability

High

CVE-2022-41125

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

High

CVE-2022-41120

Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability

High

CVE-2022-41118

Windows Scripting Languages Remote Code Execution Vulnerability

Medium

CVE-2022-41116

Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability

High

CVE-2022-41114

Windows Bind Filter Driver Elevation of Privilege Vulnerability

High

CVE-2022-41113

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

High

CVE-2022-41109

Windows Win32k Elevation of Privilege Vulnerability

High

CVE-2022-41102

Windows Overlay Filter Elevation of Privilege Vulnerability

High

CVE-2022-41101

Windows Overlay Filter Elevation of Privilege Vulnerability

High

CVE-2022-41100

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

Medium

CVE-2022-41098

Windows GDI+ Information Disclosure Vulnerability

High

CVE-2022-41095

Windows Digital Media Receiver Elevation of Privilege Vulnerability

High

CVE-2022-41093

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

High

CVE-2022-41092

Windows Win32k Elevation of Privilege Vulnerability

Medium

CVE-2022-41091

Windows Mark of the Web Security Feature Bypass Vulnerability

Medium

CVE-2022-41090

Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability

High

CVE-2022-41088

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

Medium

CVE-2022-41086

Windows Group Policy Elevation of Privilege Vulnerability

High

CVE-2022-41073

Windows Print Spooler Elevation of Privilege Vulnerability

High

CVE-2022-41058

Windows Network Address Translation (NAT) Denial of Service Vulnerability

High

CVE-2022-41057

Windows HTTP.sys Elevation of Privilege Vulnerability

Medium

CVE-2022-41055

Windows Human Interface Device Information Disclosure Vulnerability

High

CVE-2022-41054

Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

High

CVE-2022-41053

Windows Kerberos Denial of Service Vulnerability

High

CVE-2022-41052

Windows Graphics Component Remote Code Execution Vulnerability

High

CVE-2022-41050

Windows Extensible File Allocation Table Elevation of Privilege Vulnerability

Medium

CVE-2022-41049

Windows Mark of the Web Security Feature Bypass Vulnerability

High

CVE-2022-41045

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

High

CVE-2022-41044

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

High

CVE-2022-41039

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

Medium

CVE-2022-38015

Windows Hyper-V Denial of Service Vulnerability

High

CVE-2022-38014

Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability

High

CVE-2022-37992

Windows Group Policy Elevation of Privilege Vulnerability

High

CVE-2022-37967

Windows Kerberos Elevation of Privilege Vulnerability

High

CVE-2022-37966

Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability

High

CVE-2022-27674

Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to a Windows kernel crash resulting in denial of service.

High

CVE-2022-23831

Insufficient validation of the IOCTL input buffer in AMD μProf may allow an attacker to send an arbitrary buffer leading to a potential Windows kernel crash resulting in denial of service.

High

CVE-2021-34579

In Phoenix Contact: FL MGUARD DM version 1.12.0 and 1.13.0 access to the Apache web server being installed as part of the FL MGUARD DM on Microsoft Windows does not require login credentials even if…

2022-11-08
Critical

CVE-2022-34825

Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X…

Critical

CVE-2022-34824

Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EX…

Critical

CVE-2022-34823

Buffer overflow vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.…

Critical

CVE-2022-34822

Path traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0…

High

CVE-2022-36077

The Electron framework enables writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 21.0.0-beta.1, 20.0.1, 19.0.11, and 18.3.7, Electron is vulnerable to E…

2022-11-07
High

CVE-2022-44747

Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107.

Medium

CVE-2022-44746

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107.

Medium

CVE-2022-44745

Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107.

High

CVE-2022-44744

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107.

High

CVE-2022-44733

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39900.

High

CVE-2022-44732

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39900.

Medium

CVE-2021-42205

ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows local users to cause a system crash by sending a certain IOCTL request, because tha…

Medium

CVE-2022-2188

Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak directory controls in the logs directory. This can le…

2022-11-04
Medium

CVE-2022-40263

BD Totalys MultiProcessor, versions 1.70 and earlier, contain hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic pr…

2022-11-03
Low

CVE-2022-3258

Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentication Abuse.

2022-11-02
High

CVE-2022-41716

Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL v…

2022-11-01
High

CVE-2022-26717

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, Safari 15.5, iTunes 12.12.4 for Win…

High

CVE-2022-3369

An Improper Access Control vulnerability in the bdservicehost.exe component, as used in Bitdefender Engines for Windows, allows an attacker to delete privileged registry keys by pointing a Registry s…

2022-10-31
High

CVE-2022-28763

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the maliciou…

2022-10-28
Medium

CVE-2022-3734

A vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unknown code in the library C:/Program Files/Redis/dbghelp.dll. The manipulation lea…

2022-10-25
High

CVE-2022-39327

Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code injection. Critical scenarios are where a hosting ma…

2022-10-24
High

CVE-2022-41796

Untrusted search path vulnerability in the installer of Content Transfer (for Windows) Ver.1.3 and prior allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

2022-10-21
High

CVE-2022-36122

The Automox Agent before 40 on Windows incorrectly sets permissions on key files.

2022-10-18
High

CVE-2022-39427

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.40. Easily exploitable vulnerability allows low pri…

High

CVE-2022-39421

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.40. Easily exploitable vulnerability allows low pri…

Medium

CVE-2022-21606

Vulnerability in the Oracle Services for Microsoft Transaction Server component of Oracle Database Server. The supported version that is affected is 19c. Easily exploitable vulnerability allows unaut…

Medium

CVE-2022-36439

AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp directory and delete another more privileged file via…

High

CVE-2022-36438

AsusSwitch.exe on ASUS personal computers (running Windows) sets weak file permissions, leading to local privilege escalation (this also can be used to delete files within the system arbitrarily). Th…

2022-10-17
High

CVE-2022-3368

A vulnerability within the Software Updater functionality of Avira Security for Windows allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The i…

Critical

CVE-2022-2052

Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use these accounts to remotely gain full access to the system.

2022-10-11
High

CVE-2022-41184

Due to lack of proper memory management, when a victim opens a manipulated Windows Cursor File (.cur, ico.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it…

Medium

CVE-2022-41183

Due to lack of proper memory management, when a victim opens manipulated Windows Cursor File (.cur, ico.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is…

High

CVE-2022-41081

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

High

CVE-2022-41033

Windows COM+ Event System Service Elevation of Privilege Vulnerability

High

CVE-2022-38051

Windows Graphics Component Elevation of Privilege Vulnerability

High

CVE-2022-38047

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

High

CVE-2022-38045

Windows Server Service Elevation of Privilege Vulnerability

High

CVE-2022-38044

Windows CD-ROM File System Driver Remote Code Execution Vulnerability

Medium

CVE-2022-38043

Windows Security Support Provider Interface Information Disclosure Vulnerability

High

CVE-2022-38041

Windows Secure Channel Denial of Service Vulnerability

High

CVE-2022-38039

Windows Kernel Elevation of Privilege Vulnerability

High

CVE-2022-38038

Windows Kernel Elevation of Privilege Vulnerability

High

CVE-2022-38037

Windows Kernel Elevation of Privilege Vulnerability

High

CVE-2022-38034

Windows Workstation Service Elevation of Privilege Vulnerability

Medium

CVE-2022-38033

Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability

Medium

CVE-2022-38032

Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability

Medium

CVE-2022-38030

Windows USB Serial Driver Information Disclosure Vulnerability

High

CVE-2022-38029

Windows ALPC Elevation of Privilege Vulnerability

High

CVE-2022-38028

Windows Print Spooler Elevation of Privilege Vulnerability

High

CVE-2022-38027

Windows Storage Elevation of Privilege Vulnerability

Medium

CVE-2022-38026

Windows DHCP Client Information Disclosure Vulnerability

Medium

CVE-2022-38025

Windows Distributed File System (DFS) Information Disclosure Vulnerability

Low

CVE-2022-38022

Windows Kernel Elevation of Privilege Vulnerability

High

CVE-2022-38016

Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability

High

CVE-2022-38003

Windows Resilient File System Elevation of Privilege

High

CVE-2022-38000

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

High

CVE-2022-37999

Windows Group Policy Preference Client Elevation of Privilege Vulnerability

High

CVE-2022-37998

Windows Local Session Manager (LSM) Denial of Service Vulnerability

High

CVE-2022-37997

Windows Graphics Component Elevation of Privilege Vulnerability

Medium

CVE-2022-37996

Windows Kernel Memory Information Disclosure Vulnerability

High

CVE-2022-37995

Windows Kernel Elevation of Privilege Vulnerability

High

CVE-2022-37994

Windows Group Policy Preference Client Elevation of Privilege Vulnerability

High

CVE-2022-37993

Windows Group Policy Preference Client Elevation of Privilege Vulnerability

High

CVE-2022-37991

Windows Kernel Elevation of Privilege Vulnerability

High

CVE-2022-37990

Windows Kernel Elevation of Privilege Vulnerability

High

CVE-2022-37989

Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

High

CVE-2022-37988

Windows Kernel Elevation of Privilege Vulnerability

High

CVE-2022-37987

Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

High

CVE-2022-37986

Windows Win32k Elevation of Privilege Vulnerability

Medium

CVE-2022-37985

Windows Graphics Component Information Disclosure Vulnerability

High

CVE-2022-37984

Windows WLAN Service Elevation of Privilege Vulnerability

Medium

CVE-2022-37981

Windows Event Logging Service Denial of Service Vulnerability

High

CVE-2022-37980

Windows DHCP Client Elevation of Privilege Vulnerability

High

CVE-2022-37979

Windows Hyper-V Elevation of Privilege Vulnerability

High

CVE-2022-37978

Windows Active Directory Certificate Services Security Feature Bypass

High

CVE-2022-37975

Windows Group Policy Elevation of Privilege Vulnerability