« Volver al listado

Microsoft

Microsoft Windows 7: vulnerabilidades y CVE

Microsoft Windows 7 tiene 2369 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 41 son críticas y 100 figuran en el catálogo de explotación activa de CISA.

CVE2369
Últimos 12 meses0
Críticas41
Explotadas activamente100

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2013-3918Alta (8.8)74%⚠ Explotación activa12 nov 2013
The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows…
CVE-2021-43226Alta (7.8)3.1%⚠ Explotación activa15 dic 2021
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2011-3402Alta (8.8)78%⚠ Explotación activa4 nov 2011
Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2…
CVE-2018-8639Alta (7.8)22%⚠ Explotación activa12 dic 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server…
CVE-2018-0824Alta (8.8)73%⚠ Explotación activa9 may 2018
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows…
CVE-2016-0165Alta (7.8)14%⚠ Explotación activa12 abr 2016
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to…
CVE-2019-1388Alta (7.8)8.6%⚠ Explotación activa12 nov 2019
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'.
CVE-2022-41073Alta (7.8)2.3%⚠ Explotación activa9 nov 2022
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2022-41128Alta (8.8)25%⚠ Explotación activa9 nov 2022
Windows Scripting Languages Remote Code Execution Vulnerability
CVE-2022-41033Alta (7.8)1.7%⚠ Explotación activa11 oct 2022
Windows COM+ Event System Service Elevation of Privilege Vulnerability
CVE-2010-2568Alta (7.8)91%⚠ Explotación activa22 jul 2010
Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF…
CVE-2022-37969Alta (7.8)28%⚠ Explotación activa13 sept 2022
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2022-34713Alta (7.8)68%⚠ Explotación activa9 ago 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
CVE-2022-22047Alta (7.8)19%⚠ Explotación activa12 jul 2022
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
CVE-2022-26925Media (5.9)10%⚠ Explotación activa10 may 2022
Windows LSA Spoofing Vulnerability
CVE-2022-30190Alta (7.8)99%⚠ Explotación activa1 jun 2022
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the…
CVE-2012-0151Alta (7.8)88%⚠ Explotación activa10 abr 2012
The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer…
CVE-2014-4148Alta (8.8)60%⚠ Explotación activa15 oct 2014
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT…
CVE-2014-4077Alta (7.8)55%⚠ Explotación activa11 nov 2014
Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka IME for Japanese) is installed, allow remote attackers to bypass a…
CVE-2015-0016Alta (7.8)76%⚠ Explotación activa13 ene 2015
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2024-23594Media (6.4)0.24%—15 abr 2024
A buffer overflow vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to 2014 that could allow a privileged attacker with local…
CVE-2024-23593Media (6.7)0.33%—15 abr 2024
A vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to 2014 that could allow a privileged attacker with local access to modify…
CVE-2023-34367Media (6.5)1.2%—14 jun 2023
Windows 7 is vulnerable to a full blind TCP/IP hijacking attack. The vulnerability exists in Windows 7 (any Windows until Windows 8) and in any implementation of TCP/IP, which is vulnerable to the Idle scan attack…
CVE-2022-35759Media (6.5)1.7%—31 may 2023
Windows Local Security Authority (LSA) Denial of Service Vulnerability
CVE-2022-35758Media (5.5)0.50%—31 may 2023
Windows Kernel Memory Information Disclosure Vulnerability
CVE-2022-35756Alta (7.8)11%—31 may 2023
Windows Kerberos Elevation of Privilege Vulnerability
CVE-2022-35754Media (6.7)0.41%—31 may 2023
Unified Write Filter Elevation of Privilege Vulnerability
CVE-2022-35753Alta (8.1)1.2%—31 may 2023
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CVE-2022-35752Alta (8.1)1.2%—31 may 2023
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CVE-2022-35751Alta (7.8)5.5%—31 may 2023
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2022-35750Alta (7.8)6.5%—31 may 2023
Win32k Elevation of Privilege Vulnerability
CVE-2022-35747Media (5.9)1.7%—31 may 2023
Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
CVE-2022-35745Alta (8.1)1.2%—31 may 2023
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CVE-2022-35744Crítica (9.8)2.0%—31 may 2023
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
CVE-2022-35743Alta (7.8)1.5%—31 may 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
CVE-2023-21776Media (5.5)1.0%—10 ene 2023
Windows Kernel Information Disclosure Vulnerability
CVE-2023-21774Alta (7.8)0.72%—10 ene 2023
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-21773Alta (7.8)0.70%—10 ene 2023
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-21772Alta (7.8)0.72%—10 ene 2023
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-21765Alta (7.8)0.47%—10 ene 2023
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2023-21760Alta (7.1)0.53%—10 ene 2023
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2023-21757Alta (7.5)2.0%—10 ene 2023
Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability
CVE-2023-21755Alta (7.8)0.49%—10 ene 2023
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-21754Alta (7.8)0.46%—10 ene 2023
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-21752Alta (7.1)5.3%—10 ene 2023
Windows Backup Service Elevation of Privilege Vulnerability
CVE-2023-21750Alta (7.1)0.71%—10 ene 2023
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-21749Alta (7.8)0.81%—10 ene 2023
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-21748Alta (7.8)0.83%—10 ene 2023
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-21747Alta (7.8)0.83%—10 ene 2023
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-21746Alta (7.8)2.5%—10 ene 2023
Windows NTLM Elevation of Privilege Vulnerability

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation50
  2. T1203 Exploitation for Client Execution40
  3. T1059 Command and Scripting Interpreter37
  4. T1005 Data from Local System6
  5. T1190 Exploit Public-Facing Application5
  6. T1210 Exploitation of Remote Services4

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft