Microsoft
91,472 known vulnerabilities
Top Products
A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properly handle objects in
An elevation of privilege exists in SyncController.dll. An attacker who successfully exploited the vulnerability could r
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerabil
A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins.
An elevation of privilege vulnerability exists in the way that the Windows kernel image handles objects in memory. An at
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file
A denial of service vulnerability exists when the XmlLite runtime (XmlLite.dll) improperly parses XML input. An attacker
An elevation of privilege vulnerability exists in the way that the wcmsvc.dll handles objects in memory. An attacker who
An elevation of privilege vulnerability exists due to a stack corruption in Windows Subsystem for Linux. An attacker who
An elevation of privilege vulnerability exists when Windows Core Shell COM Server Registrar improperly handles COM calls
This information is being revised to indicate that this CVE (CVE-2019-1183) is fully mitigated by the security updates f
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an
An elevation of privilege vulnerability exists in the way that the wcmsvc.dll handles objects in memory. An attacker who
An elevation of privilege vulnerability exists in the way that the unistore.dll handles objects in memory. An attacker w
An elevation of privilege vulnerability exists in the way that the ssdpsrv.dll handles objects in memory. An attacker wh
An elevation of privilege vulnerability exists in the way that the rpcss.dll handles objects in memory. An attacker who
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who succes
An elevation of privilege vulnerability exists in the way that the psmsrv.dll handles objects in memory. An attacker who
An elevation of privilege vulnerability exists in the way that the PsmServiceExtHost.dll handles objects in memory. An a
An elevation of privilege vulnerability exists in the way that the PsmServiceExtHost.dll handles objects in memory. An a
An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login
An information disclosure vulnerability exists in SymCrypt during the OAEP decryption stage. An attacker who successfull
An elevation of privilege vulnerability exists when reparse points are created by sandboxed processes allowing sandbox e
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
An elevation of privilege exists in the p2pimsvc service where an attacker who successfully exploited the vulnerability
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An at
A security feature bypass exists when Windows incorrectly validates CAB file signatures. An attacker who successfully ex
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary loc
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An at
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory.
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory.
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory.
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory.
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory.
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started