« Volver al listado

Microsoft

Microsoft Windows RT 8.1: vulnerabilidades y CVE

Microsoft Windows RT 8.1 tiene 2020 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 36 son críticas y 87 figuran en el catálogo de explotación activa de CISA.

CVE2020
Últimos 12 meses0
Críticas36
Explotadas activamente87

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2013-3918Alta (8.8)74%⚠ Explotación activa12 nov 2013
The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows…
CVE-2021-43226Alta (7.8)3.1%⚠ Explotación activa15 dic 2021
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2018-8639Alta (7.8)22%⚠ Explotación activa12 dic 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server…
CVE-2018-0824Alta (8.8)73%⚠ Explotación activa9 may 2018
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows…
CVE-2022-38028Alta (7.8)15%⚠ Explotación activa11 oct 2022
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2016-0165Alta (7.8)14%⚠ Explotación activa12 abr 2016
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to…
CVE-2019-1388Alta (7.8)8.6%⚠ Explotación activa12 nov 2019
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'.
CVE-2023-21674Alta (8.8)41%⚠ Explotación activa10 ene 2023
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
CVE-2022-41033Alta (7.8)1.7%⚠ Explotación activa11 oct 2022
Windows COM+ Event System Service Elevation of Privilege Vulnerability
CVE-2022-37969Alta (7.8)28%⚠ Explotación activa13 sept 2022
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2022-26923Alta (8.8)84%⚠ Explotación activa10 may 2022
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2022-34713Alta (7.8)68%⚠ Explotación activa9 ago 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
CVE-2022-22047Alta (7.8)19%⚠ Explotación activa12 jul 2022
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
CVE-2022-26925Media (5.9)10%⚠ Explotación activa10 may 2022
Windows LSA Spoofing Vulnerability
CVE-2022-30190Alta (7.8)99%⚠ Explotación activa1 jun 2022
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the…
CVE-2015-0016Alta (7.8)76%⚠ Explotación activa13 ene 2015
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and…
CVE-2015-2360Alta (8.8)15%⚠ Explotación activa10 jun 2015
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and…
CVE-2015-1769Media (6.6)4.1%⚠ Explotación activa15 ago 2015
Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks,…
CVE-2014-4148Alta (8.8)60%⚠ Explotación activa15 oct 2014
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT…
CVE-2016-3393Alta (7.8)68%⚠ Explotación activa14 oct 2016
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2022-35759Media (6.5)1.7%—31 may 2023
Windows Local Security Authority (LSA) Denial of Service Vulnerability
CVE-2022-35758Media (5.5)0.50%—31 may 2023
Windows Kernel Memory Information Disclosure Vulnerability
CVE-2022-35756Alta (7.8)11%—31 may 2023
Windows Kerberos Elevation of Privilege Vulnerability
CVE-2022-35755Alta (7.3)9.8%—31 may 2023
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2022-35754Media (6.7)0.41%—31 may 2023
Unified Write Filter Elevation of Privilege Vulnerability
CVE-2022-35753Alta (8.1)1.2%—31 may 2023
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CVE-2022-35752Alta (8.1)1.2%—31 may 2023
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CVE-2022-35751Alta (7.8)5.5%—31 may 2023
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2022-35750Alta (7.8)6.5%—31 may 2023
Win32k Elevation of Privilege Vulnerability
CVE-2022-35749Alta (7.8)0.55%—31 may 2023
Windows Digital Media Receiver Elevation of Privilege Vulnerability
CVE-2022-35747Media (5.9)1.7%—31 may 2023
Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
CVE-2022-35746Alta (7.8)0.55%—31 may 2023
Windows Digital Media Receiver Elevation of Privilege Vulnerability
CVE-2022-35745Alta (8.1)1.2%—31 may 2023
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CVE-2022-35744Crítica (9.8)2.0%—31 may 2023
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
CVE-2022-35743Alta (7.8)1.5%—31 may 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
CVE-2023-21712Alta (8.1)0.99%—27 abr 2023
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
CVE-2023-21776Media (5.5)1.0%—10 ene 2023
Windows Kernel Information Disclosure Vulnerability
CVE-2023-21774Alta (7.8)0.72%—10 ene 2023
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-21773Alta (7.8)0.70%—10 ene 2023
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-21772Alta (7.8)0.72%—10 ene 2023
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-21767Alta (7.8)0.46%—10 ene 2023
Windows Overlay Filter Elevation of Privilege Vulnerability
CVE-2023-21765Alta (7.8)0.47%—10 ene 2023
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2023-21760Alta (7.1)0.53%—10 ene 2023
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2023-21757Alta (7.5)2.0%—10 ene 2023
Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability
CVE-2023-21755Alta (7.8)0.49%—10 ene 2023
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-21754Alta (7.8)0.46%—10 ene 2023
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-21750Alta (7.1)0.71%—10 ene 2023
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-21749Alta (7.8)0.81%—10 ene 2023
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-21748Alta (7.8)0.83%—10 ene 2023
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-21747Alta (7.8)0.83%—10 ene 2023
Windows Kernel Elevation of Privilege Vulnerability

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation64
  2. T1059 Command and Scripting Interpreter41
  3. T1203 Exploitation for Client Execution17
  4. T1059.001 PowerShell15
  5. T1005 Data from Local System4
  6. T1548.002 Bypass User Account Control4

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft