Vendor
Microsoft, page 2
As of , 389 Microsoft vulnerabilities are on CISA's list of exploited vulnerabilities, 117 of them used in ransomware campaigns; 40 were added in 2026. Patch first: CVE-2019-1068.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 26 | CVE-2017-0147Windows SMBv1 Information Disclosure | Microsoft SMBv1 server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 27 | CVE-2014-0322Use-After-Free | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.85; verified Exploit-DB entry | 0.85 | ||
| 28 | CVE-2014-4113Privilege Escalation | Microsoft Win32k | Patch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry | 0.87 | ||
| 29 | CVE-2017-0148Remote Code Execution | Microsoft SMBv1 server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 30 | CVE-2013-2551Use-After-Free | Microsoft Internet Explorer | Patch this weekRansomware use; Metasploit module; EPSS 0.74; verified Exploit-DB entry | 0.74 | ||
| 31 | CVE-2015-2426Adobe Type Manager Library Remote Code Execution | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry | 0.87 | ||
| 32 | CVE-2014-6324Privilege Escalation | Microsoft Kerberos Key Distribution Center (KDC) | Patch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry | 0.87 | ||
| 33 | CVE-2014-6332Object Linking & Embedding (OLE) Automation Array Remote Code Execution | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.95; verified Exploit-DB entry | 0.95 | ||
| 34 | CVE-2017-0146SMB Remote Code Execution | Microsoft Windows | Patch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry | 0.90 | ||
| 35 | CVE-2018-8120Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use; Metasploit module; EPSS 0.73; verified Exploit-DB entry | 0.73 | ||
| 36 | CVE-2009-3129Featheader Record Memory Corruption | Microsoft Excel | Patch this weekMetasploit module; EPSS 0.84; verified Exploit-DB entry | 0.84 | ||
| 37 | CVE-2010-3333Stack-based Buffer Overflow | Microsoft Office | Patch this weekMetasploit module; EPSS 0.89; verified Exploit-DB entry | 0.89 | ||
| 38 | CVE-2013-1347Remote Code Execution | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.78; verified Exploit-DB entry | 0.78 | ||
| 39 | CVE-2013-3897Use-After-Free | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.77; verified Exploit-DB entry | 0.77 | ||
| 40 | CVE-2014-4114Object Linking & Embedding (OLE) Remote Code Execution | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.82; verified Exploit-DB entry | 0.82 | ||
| 41 | CVE-2015-1701Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use; Metasploit module; EPSS 0.56; verified Exploit-DB entry | 0.56 | ||
| 42 | CVE-2014-6352Code Injection | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.77; verified Exploit-DB entry | 0.77 | ||
| 43 | CVE-2013-3906Memory Corruption | Microsoft Graphics Component | Patch this weekMetasploit module; EPSS 0.85; verified Exploit-DB entry | 0.85 | ||
| 44 | CVE-2014-1761Memory Corruption | Microsoft Word | Patch this weekMetasploit module; EPSS 0.77; verified Exploit-DB entry | 0.77 | ||
| 45 | CVE-2017-0144Remote Code Execution | Microsoft SMBv1 | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 46 | CVE-2017-0145Remote Code Execution | Microsoft SMBv1 | Patch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry | 0.90 | ||
| 47 | CVE-2018-8453Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use; Metasploit module; EPSS 0.70; verified Exploit-DB entry | 0.70 | ||
| 48 | CVE-2012-0158Remote Code Execution | Microsoft MSCOMCTL.OCX | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 49 | CVE-2017-0143Server Message Block (SMBv1) Remote Code Execution | Microsoft Windows | Patch this weekRansomware use; Metasploit module; EPSS 0.93; verified Exploit-DB entry | 0.93 | ||
| 50 | CVE-2017-0199Remote Code Execution | Microsoft Office and WordPad | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 51 | CVE-2017-7269Windows Server Buffer Overflow | Microsoft Internet Information Services (IIS) | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 52 | CVE-2019-0708Remote Code Execution | Microsoft Remote Desktop Services | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 53 | CVE-2020-0646Remote Code Execution | Microsoft .NET Framework | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 54 | CVE-2020-0688Validation Key Remote Code Execution | Microsoft Exchange Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 55 | CVE-2011-2005Improper Input Validation | Microsoft Ancillary Function Driver (afd.sys) | Patch this weekMetasploit module; verified Exploit-DB entry | 0.32 | ||
| 56 | CVE-2013-3660Privilege Escalation | Microsoft Win32k | Patch this weekMetasploit module; verified Exploit-DB entry | 0.39 | ||
| 57 | CVE-2019-0841AppX Deployment Service (AppXSVC) Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module; verified Exploit-DB entry | 0.41 | ||
| 58 | CVE-2019-1405Universal Plug and Play (UPnP) Service Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module; verified Exploit-DB entry | 0.30 | ||
| 59 | CVE-2010-0232Kernel Exception Handler | Microsoft Windows | Patch this weekMetasploit module; verified Exploit-DB entry | 0.29 | ||
| 60 | CVE-2013-5065Kernel Privilege Escalation | Microsoft Windows | Patch this weekMetasploit module; verified Exploit-DB entry | 0.35 | ||
| 61 | CVE-2016-0099Secondary Logon Service Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module; verified Exploit-DB entry | 0.37 | ||
| 62 | CVE-2016-3235OLE DLL Side Loading | Microsoft Office | Patch this weekMetasploit module; verified Exploit-DB entry | 0.43 | ||
| 63 | CVE-2016-0040Kernel Privilege Escalation | Microsoft Windows | Patch this weekMetasploit module; verified Exploit-DB entry | 0.24 | ||
| 64 | CVE-2019-1322Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module; verified Exploit-DB entry | 0.19 | ||
| 65 | CVE-2025-59287Server Update Service (WSUS) Deserialization of Untrusted Data | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 66 | CVE-2011-3402Remote Code Execution | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.78 | 0.78 | ||
| 67 | CVE-2025-49704Code Injection | Microsoft SharePoint | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 68 | CVE-2025-49706Improper Authentication | Microsoft SharePoint | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 69 | CVE-2025-53770Deserialization of Untrusted Data | Microsoft SharePoint | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 70 | CVE-2025-33053External Control of File Name or Path | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.87 | 0.87 | ||
| 71 | CVE-2020-0618Reporting Services Remote Code Execution | Microsoft SQL Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 72 | CVE-2018-0824COM for Windows Deserialization of Untrusted Data | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.73 | 0.73 | ||
| 73 | CVE-2023-24955Code Injection | Microsoft SharePoint Server | Patch this weekRansomware use; Metasploit module; EPSS 0.85 | 0.85 | ||
| 74 | CVE-2023-29357Privilege Escalation | Microsoft SharePoint Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 75 | CVE-2022-41040Server-Side Request Forgery | Microsoft Exchange Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 76 | CVE-2022-41082Remote Code Execution | Microsoft Exchange Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 77 | CVE-2022-26923Domain Services Privilege Escalation | Microsoft Active Directory | Patch this weekMetasploit module; EPSS 0.84 | 0.84 | ||
| 78 | CVE-2022-30190Support Diagnostic Tool (MSDT) Remote Code Execution | Microsoft Windows | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 79 | CVE-2021-31166Remote Code Execution | Microsoft HTTP Protocol Stack | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 80 | CVE-2016-0189Memory Corruption | Microsoft Internet Explorer | Patch this weekRansomware use; Metasploit module; EPSS 0.94 | 0.94 | ||
| 81 | CVE-2015-1635Remote Code Execution | Microsoft HTTP.sys | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 82 | CVE-2017-8464Shell (.lnk) Remote Code Execution | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.90 | 0.90 | ||
| 83 | CVE-2020-0796Remote Code Execution | Microsoft SMBv3 | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 84 | CVE-2021-36934SAM Local Privilege Escalation | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.67 | 0.67 | ||
| 85 | CVE-2022-21882Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use; Metasploit module; EPSS 0.59 | 0.59 | ||
| 86 | CVE-2019-1458Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use; Metasploit module; EPSS 0.74 | 0.74 | ||
| 87 | CVE-2021-40449Win32k Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module; EPSS 0.74 | 0.74 | ||
| 88 | CVE-2021-42321Server Remote Code Execution | Microsoft Exchange | Patch this weekRansomware use; Metasploit module; EPSS 0.92 | 0.92 | ||
| 89 | CVE-2014-1812Group Policy Preferences Password Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module; EPSS 0.65 | 0.65 | ||
| 90 | CVE-2017-11882Memory Corruption | Microsoft Office | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 91 | CVE-2020-1147.NET Framework, SharePoint, and Visual Studio Remote Code Execution | Microsoft .NET Framework, SharePoint, Visual Studio | Patch this weekMetasploit module; EPSS 0.94 | 0.94 | ||
| 92 | CVE-2020-1472Privilege Escalation | Microsoft Netlogon | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 93 | CVE-2021-1675Print Spooler Remote Code Execution | Microsoft Windows | Patch this weekRansomware use; Metasploit module; EPSS 0.85 | 0.85 | ||
| 94 | CVE-2021-1732Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use; Metasploit module; EPSS 0.78 | 0.78 | ||
| 95 | CVE-2021-26855Remote Code Execution | Microsoft Exchange Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 96 | CVE-2021-27065Remote Code Execution | Microsoft Exchange Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 97 | CVE-2021-31207Security Feature Bypass | Microsoft Exchange Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 98 | CVE-2021-34473Remote Code Execution | Microsoft Exchange Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 99 | CVE-2021-34523Privilege Escalation | Microsoft Exchange Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 100 | CVE-2021-34527Print Spooler Remote Code Execution | Microsoft Windows | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 101 | CVE-2021-36942Local Security Authority (LSA) Spoofing | Microsoft Windows | Patch this weekRansomware use; Metasploit module; EPSS 0.66 | 0.66 | ||
| 102 | CVE-2021-38647Remote Code Execution | Microsoft Open Management Infrastructure (OMI) | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 103 | CVE-2021-40444Remote Code Execution | Microsoft MSHTML | Patch this weekRansomware use; Metasploit module; EPSS 0.97 | 0.97 | ||
| 104 | CVE-2023-36874Error Reporting Service Privilege Escalation | Microsoft Windows | Patch this weekMetasploit module | 0.43 | ||
| 105 | CVE-2023-28252Common Log File System (CLFS) Driver Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module | 0.49 | ||
| 106 | CVE-2013-7331Information Disclosure | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.50 | 0.50 | ||
| 107 | CVE-2022-21999Print Spooler Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module | 0.41 | ||
| 108 | CVE-2020-0787Background Intelligent Transfer Service (BITS) Improper Privilege Management | Microsoft Windows | Patch this weekRansomware use; Metasploit module | 0.43 | ||
| 109 | CVE-2019-0808Privilege Escalation | Microsoft Win32k | Patch this weekMetasploit module; EPSS 0.53 | 0.53 | ||
| 110 | CVE-2020-1054Privilege Escalation | Microsoft Win32k | Patch this weekMetasploit module; EPSS 0.54 | 0.54 | ||
| 111 | CVE-2024-35250Kernel-Mode Driver Untrusted Pointer Dereference | Microsoft Windows | Patch this weekMetasploit module | 0.25 | ||
| 112 | CVE-2018-8440Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module | 0.18 | ||
| 113 | CVE-2022-26904User Profile Service Privilege Escalation | Microsoft Windows | Patch this weekMetasploit module | 0.17 | ||
| 114 | CVE-2021-38648Privilege Escalation | Microsoft Open Management Infrastructure (OMI) | Patch this weekMetasploit module | 0.11 | ||
| 115 | CVE-2016-0151Windows CSRSS Security Feature Bypass | Microsoft Client-Server Run-time Subsystem (CSRSS) | Patch this weekRansomware use; EPSS 0.63; verified Exploit-DB entry | 0.63 | ||
| 116 | CVE-2016-7200Memory Corruption | Microsoft Edge | Patch this weekEPSS 0.83; verified Exploit-DB entry | 0.83 | ||
| 117 | CVE-2016-7201Memory Corruption | Microsoft Edge | Patch this weekEPSS 0.80; verified Exploit-DB entry | 0.80 | ||
| 118 | CVE-2017-0037Type Confusion | Microsoft Edge and Internet Explorer | Patch this weekEPSS 0.80; verified Exploit-DB entry | 0.80 | ||
| 119 | CVE-2017-0059Information Disclosure | Microsoft Internet Explorer | Patch this weekEPSS 0.62; verified Exploit-DB entry | 0.62 | ||
| 120 | CVE-2017-0213Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; EPSS 0.84; verified Exploit-DB entry | 0.84 | ||
| 121 | CVE-2017-8540Improper Restriction of Operations | Microsoft Malware Protection Engine | Patch this weekEPSS 0.72; verified Exploit-DB entry | 0.72 | ||
| 122 | CVE-2016-0185Media Center Remote Code Execution | Microsoft Windows | Patch this weekEPSS 0.70; verified Exploit-DB entry | 0.70 | ||
| 123 | CVE-2019-1429Scripting Engine Memory Corruption | Microsoft Internet Explorer | Patch this weekEPSS 0.77; verified Exploit-DB entry | 0.77 | ||
| 124 | CVE-2019-0543Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; verified Exploit-DB entry | 0.05 | ||
| 125 | CVE-2024-43468SQL Injection | Microsoft Configuration Manager | Patch this weekEPSS 0.81 | 0.81 |