Skip to main content

Windows vulnerabilities

66 published alerts for Microsoft Windows.

Actively exploited (KEV)

CVE-2008-4250

Microsoft Windows Buffer Overflow Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2008-4250). Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-32202

Microsoft Windows Protection Mechanism Failure Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-32202). Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network. CISA remediation due date: 2026-05-12. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2025-60710

Microsoft Windows Link Following Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-60710). Microsoft Windows contains a link following vulnerability that allows for privilege escalation CISA remediation due date: 2026-04-27. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2023-36424

Microsoft Windows Out-of-Bounds Read Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-36424). Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation CISA remediation due date: 2026-04-27. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2008-0015

Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2008-0015). Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. CISA remediation due date: 2026-03-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-21533

Microsoft Windows Improper Privilege Management Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-21533). Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally. CISA remediation due date: 2026-03-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-21525

Microsoft Windows NULL Pointer Dereference Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-21525). Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally. CISA remediation due date: 2026-03-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-21519

Microsoft Windows Type Confusion Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-21519). Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally. CISA remediation due date: 2026-03-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-21513

Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-21513). Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. CISA remediation due date: 2026-03-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-21510

Microsoft Windows Shell Protection Mechanism Failure Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-21510). Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. CISA remediation due date: 2026-03-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-20805

Microsoft Windows Information Disclosure Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20805). Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally. CISA remediation due date: 2026-02-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-62221

Microsoft Windows Use After Free Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-62221). Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally. CISA remediation due date: 2025-12-30. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-62215

Microsoft Windows Race Condition Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-62215). Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could enable the attacker to gain SYSTEM-level access. CISA remediation due date: 2025-12-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-59287

Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-59287). Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution. CISA remediation due date: 2025-11-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-33073

Microsoft Windows SMB Client Improper Access Control Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-33073). Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate. CISA remediation due date: 2025-11-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-59230

Microsoft Windows Improper Access Control Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-59230). Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally. CISA remediation due date: 2025-11-04. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-24990

Microsoft Windows Untrusted Pointer Dereference Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-24990). Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully exploited this vulnerability could gain administrator privileges. CISA remediation due date: 2025-11-04. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2021-43226

Microsoft Windows Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-43226). Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms. CISA remediation due date: 2025-10-27. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2013-3918

Microsoft Windows Out-of-Bounds Write Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2013-3918). Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a specially crafted webpage. When a user views the webpage, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CISA remediation due date: 2025-10-27. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2011-3402

Microsoft Windows Remote Code Execution Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2011-3402). Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page. CISA remediation due date: 2025-10-27. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2025-29824

Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-29824). Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. CISA remediation due date: 2025-04-29. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2025-26633

Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-26633). Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally. CISA remediation due date: 2025-04-01. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-8639

Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-8639). Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. CISA remediation due date: 2025-03-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-49039

Microsoft Windows Task Scheduler Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-49039). Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions. CISA remediation due date: 2024-12-03. If you need help checking exposure, call (864) 335-9223.