M

Microsoft Security Vulnerabilities (CVE)

Explore vulnerabilities and security advisories affecting Microsoft products.

121 known CVE vulnerabilities tracked

Critical
12
High
79
Medium
28
Low
2
None
0

Vulnerabilities By Year

Products Affected

All Microsoft CVEs

CVE-2022-24451
7.8 high

VP9 Video Extensions Remote Code Execution Vulnerability

Vp9 Video Extensions Mar 9, 2022
CVE-2022-23282
7.8 high

Paint 3D Remote Code Execution Vulnerability

Paint 3D Mar 9, 2022
CVE-2022-22709
7.8 high

VP9 Video Extensions Remote Code Execution Vulnerability

Vp9 Video Extensions Feb 9, 2022
CVE-2022-21841
7.8 high

Microsoft Excel Remote Code Execution Vulnerability

365 Apps Jan 11, 2022
CVE-2022-21840
8.8 high

Microsoft Office Remote Code Execution Vulnerability

Excel Jan 11, 2022
CVE-2021-43875
7.8 high

Microsoft Office Graphics Remote Code Execution Vulnerability

365 Apps Dec 15, 2021
CVE-2021-43256
7.8 high

Microsoft Excel Remote Code Execution Vulnerability

365 Apps Dec 15, 2021
CVE-2021-43255
5.5 medium

Microsoft Office Trust Center Spoofing Vulnerability

365 Apps Dec 15, 2021
CVE-2021-42295
5.5 medium

Visual Basic for Applications Information Disclosure Vulnerability

365 Apps Dec 15, 2021
CVE-2021-42293
6.5 medium

Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability

365 Apps Dec 15, 2021
CVE-2021-42296
7.8 high

Microsoft Word Remote Code Execution Vulnerability

365 Apps Nov 10, 2021
CVE-2020-17091
7.8 high

Microsoft Teams Remote Code Execution Vulnerability

Teams Nov 11, 2020
CVE-2020-17003
7.8 high

<p>A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.</p> <p>An attacker who successfully exploited the vulnerability would gain execution on a victim system.</p> <p>The security update addresses the vulnerability by correcting how the Base3D ren

3D Viewer Oct 16, 2020
CVE-2020-16918
7.8 high

<p>A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.</p> <p>An attacker who successfully exploited the vulnerability would gain execution on a victim system.</p> <p>The security update addresses the vulnerability by correcting how the Base3D ren

365 Apps Oct 16, 2020
CVE-2020-1574
5.5 medium

A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code. Exploitation of the vulnerability requires that a program process a specially crafted image

Windows 10 Aug 17, 2020
CVE-2010-0806
8.8 high

Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, ak

Internet Explorer Mar 10, 2010
CVE-2010-0249
8.8 high

Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code by accessing a

Internet Explorer Jan 15, 2010
CVE-2009-2495
6.5 medium

The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which allows remote attackers to obtain sensitive information via a crafted HTML docum

Visual C\+\+ Jul 29, 2009
CVE-2009-2493
8.8 high

The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly re

Visual C\+\+ Jul 29, 2009
CVE-2009-0901
8.8 high

The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not prevent VariantClea

Visual C\+\+ Jul 29, 2009
CVE-2009-1537
8.8 high

Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted QuickTime media file, as exploited

Directx May 29, 2009
CVE-2003-1567
7.5 high

The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and authentication credentials, or bypass the HttpOnly protection mechanism, by usin

Internet Information Services Jan 15, 2009
CVE-2008-4250
9.8 critical

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by

Windows 2000 Oct 23, 2008
CVE-2005-1794
6.4 medium

Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.

Remote Desktop Connection Jun 1, 2005