Microsoft
91,472 known vulnerabilities
Top Products
Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges l
Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authori
Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.
Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privilege
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information
Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.
Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.
Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypas
Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a p
Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a phy
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.
Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locall
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized atta
Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an
Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclos
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a phys
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment S
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elev
Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized att
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose informat
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allow
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a ne
Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Sto
Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a secu
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server
Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorize
Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a netw
Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started