230 vulnerabilidades · Windows · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2012-4969
🔥 KEV Software Genérico Web Windows
8.1
HIGH
EPSS
91.8%
2012 1 PoC

Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012.

CVE-2024-21412
🔥 KEV Windows 11 version 21H2 Windows
8.1
HIGH
EPSS
93.8%
2024 CWE-693 2 PoCs

Internet Shortcut Files Security Feature Bypass Vulnerability

CVE-2017-12615
🔥 KEV Apache Tomcat Web Windows ⚡ nuclei
8.1
HIGH
EPSS
94.2%
2017 14 PoCs

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVE-2017-0037
🔥 KEV Internet Browser Web Windows
8.1
HIGH
EPSS
89.1%
2017 5 PoCs

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element.

CVE-2017-0148
🔥 KEV Windows SMB Windows
8.1
HIGH
EPSS
94.1%
2017 5 PoCs

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0146.

CVE-2019-0841
🔥 KEV Windows Windows
7.8
HIGH
EPSS
82.7%
2019 11 PoCs

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836.

CVE-2023-32046
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
42.7%
2023 1 PoC

Windows MSHTML Platform Elevation of Privilege Vulnerability

CVE-2015-7645
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
85.2%
2015 3 PoCs

Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.

CVE-2019-0863
🔥 KEV Windows Windows
7.8
HIGH
EPSS
6.2%
2019 1 PoC

An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.

CVE-2019-1132
🔥 KEV Windows Windows
7.8
HIGH
EPSS
36.5%
2019 2 PoCs

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

CVE-2014-4114
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
92.1%
2014 3 PoCs

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object in an Office document, as exploited in the wild with a "Sandworm" attack in June through October 2014, aka "Windows OLE Remote Code Execution Vulnerability."

CVE-2013-5065
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
73.6%
2013 1 PoC

NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013.

CVE-2015-0313
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
92.5%
2015 3 PoCs

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.

CVE-2019-1385
🔥 KEV Windows Windows
7.8
HIGH
EPSS
0.5%
2019 2 PoCs

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'.

CVE-2019-0803
🔥 KEV Windows Windows
7.8
HIGH
EPSS
89.8%
2019 3 PoCs

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0859.

CVE-2019-1064
🔥 KEV Windows 10 Version 1703 Windows
7.8
HIGH
EPSS
12.2%
2019 3 PoCs

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change or delete data. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The security update addresses the vulnerability by correcting how Windows AppX Dep