Microsoft Vulnerabilities and Affected Products
Vulnerabilities associated with Win32k.
Products
Clear product- Windows Server 20194,131 vulnerabilities
- Windows Server 2019 (Server Core installation)4,034 vulnerabilities
- Windows 10 Version 18093,762 vulnerabilities
- Windows Server 20163,677 vulnerabilities
- Windows Server 20223,485 vulnerabilities
- Windows Server 2016 (Server Core installation)3,473 vulnerabilities
- Windows 10 Version 16073,184 vulnerabilities
- Windows 10 Version 21H23,063 vulnerabilities
- Windows Server 2012 R22,998 vulnerabilities
- Windows Server 2012 R2 (Server Core installation)2,853 vulnerabilities
- Windows Server 20122,824 vulnerabilities
- Windows Server 2012 (Server Core installation)2,691 vulnerabilities
- Windows 10 Version 22H22,565 vulnerabilities
- Windows 10 Version 15072,277 vulnerabilities
- Windows 11 Version 24H21,924 vulnerabilities
- Windows Server 20251,917 vulnerabilities
- Windows Server 2025 (Server Core installation)1,917 vulnerabilities
- Windows Server 2008 R2 Service Pack 11,874 vulnerabilities
- Windows Server 2008 R2 Service Pack 1 (Server Core installation)1,860 vulnerabilities
- Windows 11 Version 23H21,845 vulnerabilities
- Windows 11 version 22H21,776 vulnerabilities
- Windows Server 2022, 23H2 Edition (Server Core installation)1,725 vulnerabilities
- Windows Server 2008 Service Pack 2 (Server Core installation)1,667 vulnerabilities
- Windows Server 2008 Service Pack 21,664 vulnerabilities
- Windows 11 version 21H21,560 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-29336HIGH | Win32k Elevation of Privilege VulnerabilityWin32k Elevation of Privilege Vulnerability CWE-416May 9, 2023 | CVSS7.8v3.1 | EPSS40.9% | PoCs2 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-21882HIGH | Win32k Elevation of Privilege VulnerabilityWin32k Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21887. | CVSS7.0v3.1 | EPSS54.6% | PoCs7 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-41357HIGH | Win32k Elevation of Privilege VulnerabilityWin32k Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-40449, CVE-2021-40450. CWE-269Oct 13, 2021 | CVSS7.8v3.1 | EPSS2.08% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-40450HIGH | Win32k Elevation of Privilege VulnerabilityWin32k Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-40449, CVE-2021-41357. CWE-269Oct 13, 2021 | CVSS7.8v3.1 | EPSS2.08% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28310HIGH | Win32k Elevation of Privilege VulnerabilityWin32k Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-27072. | CVSS7.8v3.1 | EPSS8.33% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-1732HIGH | Windows Win32k Elevation of Privilege VulnerabilityWindows Win32k Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1698. | CVSS7.8v3.1 | EPSS77.8% | PoCs10 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2020-1054HIGH | Microsoft Win32k Privilege Escalation VulnerabilityAn elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1143. | CVSS7.8v3.1 | EPSS52.8% | PoCs4 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-1458HIGH | Microsoft Win32k Privilege Escalation VulnerabilityAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. Dec 10, 2019 | CVSS7.8v3.1 | EPSS73.9% | PoCs4 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2019-1132HIGH | Microsoft Win32k Privilege Escalation VulnerabilityAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. Jul 29, 2019 | CVSS7.8v3.1 | EPSS9.79% | PoCs3 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-0859HIGH | Microsoft Win32k Privilege Escalation VulnerabilityAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0803. Apr 9, 2019 | CVSS7.8v3.1 | EPSS4.15% | PoCs1 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2019-0803HIGH | Microsoft Win32k Privilege Escalation VulnerabilityAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0859. Apr 9, 2019 | CVSS7.8v3.1 | EPSS45.2% | PoCs2 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2019-0797HIGH | Microsoft Win32k Privilege Escalation VulnerabilityAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0808. Apr 9, 2019 | CVSS7.8v3.1 | EPSS1.89% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-0808HIGH | Microsoft Win32k Privilege Escalation VulnerabilityAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0797. Apr 9, 2019 | CVSS7.8v3.1 | EPSS53% | PoCs3 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-8589HIGH | Microsoft Win32k Privilege Escalation VulnerabilityAn elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. Nov 14, 2018 | CVSS7.8v3.1 | EPSS3.02% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-8453HIGH | Microsoft Win32k Privilege Escalation VulnerabilityAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. CWE-404Oct 10, 2018 | CVSS7.8v3.1 | EPSS70% | PoCs2 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2018-8120HIGH | Microsoft Win32k Privilege Escalation VulnerabilityAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166. CWE-404May 9, 2018 | CVSS7.0v3.1 | EPSS73.7% | PoCs7 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2017-0263HIGH | Microsoft Win32k Privilege Escalation VulnerabilityThe kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." CWE-416May 12, 2017 | CVSS7.8v3.1 | EPSS10% | PoCs2 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-7255HIGH | Microsoft Win32k Privilege Escalation VulnerabilityThe kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." CWE-264Nov 10, 2016 | CVSS7.8v3.1 | EPSS81% | PoCs9 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2016-0165HIGH | Microsoft Win32k Privilege Escalation VulnerabilityThe kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0143 and CVE-2016-0167. CWE-264Apr 12, 2016 | CVSS7.8v3.1 | EPSS13.8% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-0167HIGH | Microsoft Win32k Privilege Escalation VulnerabilityThe kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0143 and CVE-2016-0165. CWE-264Apr 12, 2016 | CVSS7.8v3.1 | EPSS5.73% | PoCs0 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2015-2546HIGH | Microsoft Win32k Memory Corruption VulnerabilityThe kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2518. CWE-119Sep 9, 2015 | CVSS8.2v3.1 | EPSS10.9% | PoCs1 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2015-2360HIGH | Microsoft Win32k Privilege Escalation Vulnerabilitywin32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." | CVSS8.8v3.1 | EPSS15% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2015-1701HIGH | Microsoft Win32k Privilege Escalation VulnerabilityWin32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulnerability." CWE-264Apr 21, 2015 | CVSS7.8v3.1 | EPSS56.2% | PoCs6 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2014-4113HIGH | Microsoft Win32k Privilege Escalation Vulnerabilitywin32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka "Win32k.sys Elevation of Privilege Vulnerability." CWE-264Oct 15, 2014 | CVSS7.8v3.1 | EPSS87% | PoCs12 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2013-3660HIGH | Microsoft Win32k Privilege Escalation VulnerabilityThe EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making ma… CWE-119May 24, 2013 | CVSS7.8v3.1 | EPSS39.6% | PoCs5 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |