CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “microsoft”

377 vulnerabilities found for “microsoft”

Page 1 of 19

CVE-2026-21536
CRITICAL9.8

Microsoft Devices Pricing Program Remote Code Execution Vulnerability

microsoft / devices_pricing_program
Network
Published Mar 5, 2026
Page 1 of 19
CVE-2022-0280
HIGH7.5

A race condition vulnerability exists in the QuickClean feature of McAfee Total Protection for Windows prior to 16.0.43 that allows a local user to gain privilege elevation and perform an arbitrary file delete. This could lead to sensitive files being deleted and potentially cause denial of service. This attack exploits the way symlinks are created and how the product works with them.

microsoft / windows
Local
Published Mar 10, 2022
CVE-2021-43899
CRITICAL9.8

Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability

microsoft / wireless_display_adapter_firmware
Network
Published Dec 15, 2021
CVE-2021-36958
HIGH7.8

<p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p>

microsoft / windows
Local
Published Aug 12, 2021
CVE-2021-24092
HIGH7.8

Microsoft Defender Elevation of Privilege Vulnerability

microsoft / windows_defender+5
Local
Published Feb 25, 2021
CVE-2021-1647
HIGH7.8

Microsoft Defender Remote Code Execution Vulnerability

microsoft / windows_defender+4
Local
Published Jan 12, 2021
CVE-2020-16929
HIGH7.8

<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</p> <p>Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Excel. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) containing a specially crafted file designed to exploit the vulnerability. An attacker would have no way to force users to visit the website. Instead, an attacker would have to convince users to click a link, typically by way of an enticement in an email or instant message, and then convince them to open the specially crafted file.</p> <p>The security update addresses the vulnerability by correcting how Microsoft Excel handles objects in memory.</p>

microsoft / 365_apps+17
Local
Published Oct 16, 2020
CVE-2020-1461
HIGH7.1

An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.

microsoft / windows_defender+5
Local
Published Jul 14, 2020
CVE-2020-1170
HIGH7.8

An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1163.

microsoft / windows_defender+4
Local
Published Jun 9, 2020
CVE-2020-1163
HIGH7.8

An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1170.

microsoft / windows_defender+4
Local
Published Jun 9, 2020
CVE-2020-1002
HIGH7.1

An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.

microsoft / windows_defender+5
Local
Published Apr 15, 2020
CVE-2019-1255
HIGH7.5

A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denial of Service Vulnerability'.

microsoft / windows_defender+5
Network
Published Sep 23, 2019
CVE-2019-1161
HIGH7.1

An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted command that could exploit the vulnerability and delete protected files on an affected system once MpSigStub.exe ran again. The update addresses the vulnerability and blocks the arbitrary deletion.

microsoft / windows_defender+5
Local
Published Aug 14, 2019
CVE-2018-8281
HIGH7.8

A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Excel Viewer, Microsoft PowerPoint Viewer, Microsoft Office, Microsoft Office Word Viewer.

microsoft / office+4
Local
Published Jul 11, 2018
CVE-2018-8306
MEDIUM5.5

A command injection vulnerability exists in the Microsoft Wireless Display Adapter (MWDA) when the Microsoft Wireless Display Adapter does not properly manage user input, aka "Microsoft Wireless Display Adapter Command Injection Vulnerability." This affects Microsoft Wireless Display Adapter V2 Software.

microsoft / wireless_display_adapter_firmware+2
Adjacent
Published Jul 11, 2018
CVE-2018-8327
CRITICAL9.8

A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." This affects PowerShell Editor, PowerShell Extension.

microsoft / powershell+1
Network
Published Jul 11, 2018
CVE-2018-0598
HIGH7.8

Untrusted search path vulnerability in Self-extracting archive files created by IExpress bundled with Microsoft Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

microsoft / windows
Local
Published Jun 26, 2018
CVE-2018-0599
HIGH7.8

Untrusted search path vulnerability in the installer of Visual C++ Redistributable allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

microsoft / windows
Local
Published Jun 26, 2018
CVE-2018-0986
HIGH8.8

A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender, Windows Intune Endpoint Protection, Microsoft Security Essentials, Microsoft System Center Endpoint Protection, Microsoft Exchange Server, Microsoft System Center, Microsoft Forefront Endpoint Protection.

microsoft / exchange_server+8
Network
Published Apr 4, 2018
CVE-2018-0842
HIGH7.0

Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow an elevation of privilege vulnerability due to how objects in memory are handled, aka "Windows Kernel Elevation of Privilege Vulnerability".

microsoft / windows_embedded_compact+15
Local
Published Feb 15, 2018