11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2013-3660
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
70.6%
2013 4 PoCs

The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPath function calls, aka "Win32k Read AV Vulnerability."

CVE-2019-1253
🔥 KEV Windows Windows
7.8
HIGH
EPSS
31.9%
2019 6 PoCs

An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1215, CVE-2019-1278, CVE-2019-1303.

CVE-2023-29343
Windows Sysmon Windows
7.8
HIGH
EPSS
15.6%
2023 CWE-59 1 PoC

SysInternals Sysmon for Windows Elevation of Privilege Vulnerability

CVE-2025-53841
Guardicore Platform Agent Windows
7.8
HIGH
EPSS
0.0%
2025 CWE-829 1 PoC

The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.15.0, v51.12.0, v52.2.0 is affected by a local privilege escalation vulnerability. The service will attempt to read an OpenSSL configuration file from a non-existent location that standard Windows users have default write access to. This allows an unprivileged local user to create a crafted "openssl.cnf" file in that location and, by specifying the path to a custom DLL file in a custom OpenSSL engine definition, execute arbitrary commands with the privileges of the Guardicore

CVE-2014-4113
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
82.7%
2014 8 PoCs

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka "Win32k.sys Elevation of Privilege Vulnerability."

CVE-2021-35538
VM VirtualBox Database Windows
7.8
HIGH
EPSS
0.3%
2021 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.28. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability does not apply to Windows systems. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H

CVE-2024-0107
GPU Display Driver, vGPU Software, Cloud Gaming Cloud Windows
7.8
HIGH
EPSS
0.3%
2024 CWE-125 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2016-0165
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
6.2%
2016 1 PoC

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0143 and CVE-2016-0167.

CVE-2016-0185
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
80.2%
2016 1 PoC

Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Center link (aka .mcl) file, aka "Windows Media Center Remote Code Execution Vulnerability."

CVE-2016-0099
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
90.4%
2016 4 PoCs

The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly process request handles, which allows local users to gain privileges via a crafted application, aka "Secondary Logon Elevation of Privilege Vulnerability."

CVE-2020-7312
MA for Windows Windows
7.8
HIGH
EPSS
0.1%
2020 CWE-427 1 PoC

DLL Search Order Hijacking Vulnerability in the installer in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary code and escalate privileges via execution from a compromised folder.

CVE-2020-1147
🔥 KEV Microsoft SharePoint Enterprise Server Windows
7.8
HIGH
EPSS
93.4%
2020 3 PoCs

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.

CVE-2023-38141
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.3%
2023 CWE-367 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2021-43229
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
11.9%
2021 1 PoC

Windows NTFS Elevation of Privilege Vulnerability

CVE-2025-54100
Windows 10 Version 1607 Windows
7.8
HIGH
EPSS
0.2%
2025 CWE-77 2 PoCs

Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute code locally.

CVE-2023-35382
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
2.0%
2023 CWE-416 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-23144
AutoCAD Windows
7.8
HIGH
EPSS
0.4%
2024 CWE-787 1 PoC

A maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.