Microsoft Security Vulnerabilities (CVE)
Explore vulnerabilities and security advisories affecting Microsoft products.
121 known CVE vulnerabilities tracked
Vulnerabilities By Year
Products Affected
All Microsoft CVEs
Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.
External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform spoofing over a network.
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network.
Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
'.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.
Custom Question Answering Elevation of Privilege Vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network.
Windows Graphics Component Elevation of Privilege Vulnerability