Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Windows 7
Total 3087 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-26887 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2026-08-19 4.6 MEDIUM 7.8 HIGH
An elevation of privilege vulnerability exists in Microsoft Windows when Folder redirection has been enabled via Group Policy. When folder redirection file server is co-located with Terminal server, an attacker who successfully exploited the vulnerability would be able to begin redirecting another user's personal data to a created folder. To exploit the vulnerability, an attacker can create a new folder under the Folder Redirection root path and create a junction on a newly created User folder. When the new user logs in, Folder Redirection would start redirecting to the folder and copying personal data. This elevation of privilege vulnerability can only be addressed by reconfiguring Folder Redirection with Offline files and restricting permissions, and NOT via a security update for affected Windows Servers. See the FAQ section of this CVE for configuration guidance.
CVE-2021-26882 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2026-08-19 4.6 MEDIUM 7.8 HIGH
Remote Access API Elevation of Privilege Vulnerability
CVE-2021-26881 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2026-08-19 6.5 MEDIUM 7.5 HIGH
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2021-26878 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2026-08-19 4.6 MEDIUM 7.8 HIGH
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2021-26875 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2026-08-19 4.6 MEDIUM 7.8 HIGH
Windows Win32k Elevation of Privilege Vulnerability
CVE-2021-26873 1 Microsoft 7 Windows 10, Windows 7, Windows 8.1 and 4 more 2026-08-19 4.6 MEDIUM 7.0 HIGH
Windows User Profile Service Elevation of Privilege Vulnerability
CVE-2021-26872 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2026-08-19 4.6 MEDIUM 7.8 HIGH
Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-26869 1 Microsoft 7 Windows 10, Windows 7, Windows 8.1 and 4 more 2026-08-19 2.1 LOW 5.5 MEDIUM
Windows ActiveX Installer Service Information Disclosure Vulnerability
CVE-2021-26862 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2026-08-19 7.2 HIGH 7.0 HIGH
Windows Installer Elevation of Privilege Vulnerability
CVE-2021-26861 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2026-08-19 6.8 MEDIUM 7.8 HIGH
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2021-24107 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2026-08-19 2.1 LOW 5.5 MEDIUM
Windows Event Tracing Information Disclosure Vulnerability
CVE-2021-1640 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2026-08-19 4.6 MEDIUM 7.8 HIGH
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2020-1179 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2026-08-19 4.3 MEDIUM 6.5 MEDIUM
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage. The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory.
CVE-2020-1176 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2026-08-19 9.3 HIGH 7.8 HIGH
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory.
CVE-2020-1175 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2026-08-19 9.3 HIGH 7.8 HIGH
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory.
CVE-2020-1174 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2026-08-19 9.3 HIGH 7.8 HIGH
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory.
CVE-2020-1154 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2026-08-19 7.2 HIGH 7.8 HIGH
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted application to take control over the affected system. The security update addresses the vulnerability by correcting how CLFS handles objects in memory.
CVE-2020-1153 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2026-08-19 9.3 HIGH 7.8 HIGH
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have to open a specially crafted file. The security update addresses the vulnerability by correcting how Microsoft Graphics Components handle objects in memory.
CVE-2020-1150 1 Microsoft 2 Windows 7, Windows Server 2008 2026-08-19 6.8 MEDIUM 7.8 HIGH
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Foundation handles objects in memory.
CVE-2020-1149 1 Microsoft 7 Windows 10, Windows 7, Windows 8.1 and 4 more 2026-08-19 6.8 MEDIUM 7.0 HIGH
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Windows Runtime handles objects in memory.