imPC@ndo IT

Microsoft vulnerabilities

15.391 CVE

CVE-2025-32706
Exploited High 7.8

Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 11 more
0.02EPSS
CVE-2021-41357
Exploited High 7.8

Win32k Elevation of Privilege Vulnerability

microsoft windows_10_2004 · microsoft windows_10_20h2 · microsoft windows_10_21h1 · microsoft windows_11_21h2 · and 3 more
0.02EPSS
CVE-2021-40450
Exploited High 7.8

Win32k Elevation of Privilege Vulnerability

microsoft windows_10_1809 · microsoft windows_10_1909 · microsoft windows_10_2004 · microsoft windows_10_20h2 · and 6 more
0.02EPSS
CVE-2025-24991
Exploited Medium 5.5

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 11 more
0.02EPSS
CVE-2022-41091
Ransomware Medium 5.4

Windows Mark of the Web Security Feature Bypass Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · and 8 more
0.02EPSS
CVE-2025-24984
Exploited Medium 4.6

Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 10 more
0.02EPSS
CVE-2019-0797
Exploited High 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0808.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · and 9 more
0.02EPSS
CVE-2019-1129
Ransomware High 7.8

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130.

microsoft windows_10_1703 · microsoft windows_10_1709 · microsoft windows_10_1803 · microsoft windows_10_1809 · and 4 more
0.02EPSS
CVE-2025-30400
Exploited High 7.8

Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_22h2 · and 6 more
0.02EPSS
CVE-2023-28229
Exploited High 7.0

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · and 9 more
0.02EPSS
CVE-2025-24989
Exploited High 8.2

An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected cust…

microsoft power_pages
0.02EPSS
CVE-2022-41033
Exploited High 7.8

Windows COM+ Event System Service Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · and 12 more
0.02EPSS
CVE-2025-32709
Exploited High 7.8

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 11 more
0.02EPSS
CVE-2024-38107
Exploited High 7.8

Windows Power Dependency Coordinator Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 10 more
0.02EPSS
CVE-2025-21334
Exploited High 7.8

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_22h2 · microsoft windows_11_23h2 · and 3 more
0.02EPSS
CVE-2025-21418
Exploited High 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · and 10 more
0.02EPSS
CVE-2026-21514
Exploited High 7.8

Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.

microsoft 365_apps · microsoft office_long_term_servicing_channel
0.02EPSS
CVE-2019-1214
Exploited High 7.8

An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · and 12 more
0.01EPSS
CVE-2025-21335
Exploited High 7.8

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_22h2 · microsoft windows_11_23h2 · and 3 more
0.01EPSS
CVE-2025-24983
Exploited High 7.0

Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_server_2008 · microsoft windows_server_2012 · and 1 more
0.01EPSS
CVE-2024-49035
Exploited High 8.7

An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.

microsoft partner_center
0.01EPSS
CVE-2025-32701
Exploited High 7.8

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 11 more
0.01EPSS
CVE-2026-68820
Exploited High 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · and 9 more
0.00EPSS
CVE-2023-50387
High 7.5

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when ther…

fedoraproject fedora · isc bind · microsoft windows_server_2008 · microsoft windows_server_2012 · and 9 more
1.00EPSS
CVE-2025-53771
Medium 6.5

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

microsoft sharepoint_server
1.00EPSS