Microsoft Vulnerabilities and Affected Products
Vulnerabilities associated with Windows 7.
Products
Clear product- Windows Server 20194,131 vulnerabilities
- Windows Server 2019 (Server Core installation)4,034 vulnerabilities
- Windows 10 Version 18093,762 vulnerabilities
- Windows Server 20163,677 vulnerabilities
- Windows Server 20223,485 vulnerabilities
- Windows Server 2016 (Server Core installation)3,473 vulnerabilities
- Windows 10 Version 16073,184 vulnerabilities
- Windows 10 Version 21H23,063 vulnerabilities
- Windows Server 2012 R22,998 vulnerabilities
- Windows Server 2012 R2 (Server Core installation)2,853 vulnerabilities
- Windows Server 20122,824 vulnerabilities
- Windows Server 2012 (Server Core installation)2,691 vulnerabilities
- Windows 10 Version 22H22,565 vulnerabilities
- Windows 10 Version 15072,277 vulnerabilities
- Windows 11 Version 24H21,924 vulnerabilities
- Windows Server 20251,917 vulnerabilities
- Windows Server 2025 (Server Core installation)1,917 vulnerabilities
- Windows Server 2008 R2 Service Pack 11,874 vulnerabilities
- Windows Server 2008 R2 Service Pack 1 (Server Core installation)1,860 vulnerabilities
- Windows 11 Version 23H21,845 vulnerabilities
- Windows 11 version 22H21,776 vulnerabilities
- Windows Server 2022, 23H2 Edition (Server Core installation)1,725 vulnerabilities
- Windows Server 2008 Service Pack 2 (Server Core installation)1,667 vulnerabilities
- Windows Server 2008 Service Pack 21,664 vulnerabilities
- Windows 11 version 21H21,560 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-35759MEDIUM | Windows Local Security Authority (LSA) Denial of Service VulnerabilityWindows Local Security Authority (LSA) Denial of Service Vulnerability May 31, 2023 | CVSS6.5v3.1 | EPSS1.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35758MEDIUM | Windows Kernel Memory Information Disclosure VulnerabilityWindows Kernel Memory Information Disclosure Vulnerability May 31, 2023 | CVSS5.5v3.1 | EPSS0.497% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35756HIGH | Windows Kerberos Elevation of Privilege VulnerabilityWindows Kerberos Elevation of Privilege Vulnerability May 31, 2023 | CVSS7.8v3.1 | EPSS11.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35753HIGH | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution VulnerabilityWindows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability May 31, 2023 | CVSS8.1v3.1 | EPSS1.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35752HIGH | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution VulnerabilityWindows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability May 31, 2023 | CVSS8.1v3.1 | EPSS1.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35750HIGH | Win32k Elevation of Privilege VulnerabilityWin32k Elevation of Privilege Vulnerability May 31, 2023 | CVSS7.8v3.1 | EPSS6.48% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35747MEDIUM | Windows Point-to-Point Protocol (PPP) Denial of Service VulnerabilityWindows Point-to-Point Protocol (PPP) Denial of Service Vulnerability May 31, 2023 | CVSS5.9v3.1 | EPSS1.68% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35745HIGH | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution VulnerabilityWindows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability May 31, 2023 | CVSS8.1v3.1 | EPSS1.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35744CRITICAL | Windows Point-to-Point Protocol (PPP) Remote Code Execution VulnerabilityWindows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability May 31, 2023 | CVSS9.8v3.1 | EPSS1.98% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35743HIGH | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution VulnerabilityMicrosoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability CWE-94May 31, 2023 | CVSS7.8v3.1 | EPSS1.45% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21556HIGH | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution VulnerabilityWindows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2023-21543, CVE-2023-21546, CVE-2023-21555, CVE-2023-21679. CWE-191Jan 10, 2023 | CVSS8.1v3.1 | EPSS1.46% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21748HIGH | Windows Kernel Elevation of Privilege VulnerabilityWindows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21675, CVE-2023-21747, CVE-2023-21749, CVE-2023-21750, CVE-2023-21754, CVE-2023-21755, CVE-2023-21772, CVE-2023-21773, CVE-2023-21774. Jan 10, 2023 | CVSS7.8v3.1 | EPSS0.826% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21682MEDIUM | Windows Point-to-Point Protocol (PPP) Information Disclosure VulnerabilityWindows Point-to-Point Protocol (PPP) Information Disclosure Vulnerability. CWE-125Jan 10, 2023 | CVSS5.3v3.1 | EPSS1.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21773HIGH | Windows Kernel Elevation of Privilege VulnerabilityWindows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21675, CVE-2023-21747, CVE-2023-21748, CVE-2023-21749, CVE-2023-21750, CVE-2023-21754, CVE-2023-21755, CVE-2023-21772, CVE-2023-21774. | CVSS7.8v3.1 | EPSS0.702% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21557HIGH | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityWindows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability. | CVSS7.5v3.1 | EPSS2.03% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21678HIGH | Windows Print Spooler Elevation of Privilege VulnerabilityWindows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21760, CVE-2023-21765. CWE-59Jan 10, 2023 | CVSS7.8v3.1 | EPSS0.58% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21765HIGH | Windows Print Spooler Elevation of Privilege VulnerabilityWindows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21678, CVE-2023-21760. CWE-190Jan 10, 2023 | CVSS7.8v3.1 | EPSS0.466% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21679HIGH | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution VulnerabilityWindows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2023-21543, CVE-2023-21546, CVE-2023-21555, CVE-2023-21556. | CVSS8.1v3.1 | EPSS1.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21543HIGH | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution VulnerabilityWindows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2023-21546, CVE-2023-21555, CVE-2023-21556, CVE-2023-21679. CWE-400Jan 10, 2023 | CVSS8.1v3.1 | EPSS1.72% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21750HIGH | Windows Kernel Elevation of Privilege VulnerabilityWindows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21675, CVE-2023-21747, CVE-2023-21748, CVE-2023-21749, CVE-2023-21754, CVE-2023-21755, CVE-2023-21772, CVE-2023-21773, CVE-2023-21774. CWE-284Jan 10, 2023 | CVSS7.1v3.1 | EPSS0.712% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21747HIGH | Windows Kernel Elevation of Privilege VulnerabilityWindows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21675, CVE-2023-21748, CVE-2023-21749, CVE-2023-21750, CVE-2023-21754, CVE-2023-21755, CVE-2023-21772, CVE-2023-21773, CVE-2023-21774. CWE-416Jan 10, 2023 | CVSS7.8v3.1 | EPSS0.833% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21754HIGH | Windows Kernel Elevation of Privilege VulnerabilityWindows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21675, CVE-2023-21747, CVE-2023-21748, CVE-2023-21749, CVE-2023-21750, CVE-2023-21755, CVE-2023-21772, CVE-2023-21773, CVE-2023-21774. CWE-190Jan 10, 2023 | CVSS7.8v3.1 | EPSS0.459% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21730HIGH | Microsoft Cryptographic Services Elevation of Privilege VulnerabilityMicrosoft Cryptographic Services Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21551, CVE-2023-21561. | CVSS7.8v3.1 | EPSS0.521% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21563MEDIUM | BitLocker Security Feature Bypass VulnerabilityBitLocker Security Feature Bypass Vulnerability. Jan 10, 2023 | CVSS6.8v3.1 | EPSS1.55% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21728HIGH | Windows Netlogon Denial of Service VulnerabilityWindows Netlogon Denial of Service Vulnerability. CWE-400Jan 10, 2023 | CVSS7.5v3.1 | EPSS1.98% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |