Microsoft Corporation vendor intelligence
Microsoft Corporation Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Microsoft Corporation products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 30
- Known exploited vulnerabilities affecting Microsoft Corporation products
- In CISA KEV
- 30
- Records also listed in the official catalog
- Beyond CISA KEV
- 0
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- Microsoft Corporation KEVs with sensor-observed exploitation activity
The catalog gap matters for Microsoft Corporation exposure
All 30 exploited Microsoft Corporation CVEs tracked here are also listed in CISA KEV. Use product ownership and sensor evidence to prioritize within this portfolio.
- 100%
- Covered by CISA
- 0%
- Beyond CISA
- 16
- Product families
Attested Microsoft Corporation CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2017-11774
Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft... |
Microsoft Outlook | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2017-0199
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server... |
Office/WordPad | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2017-11882
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow... |
Microsoft Office | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2018-0802
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution... |
Equation Editor | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2018-0798
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution... |
Equation Editor | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2017-8759
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or... |
Microsoft .NET Framework | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2017-0143
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;... |
Windows SMB | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2017-0144
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;... |
Windows SMB | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2017-0145
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;... |
Windows SMB | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2017-0262
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle... |
Microsoft Office | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2017-0263
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT... |
Microsoft Windows | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2017-8464
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT... |
Windows Shell | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2017-0222
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption... |
Internet Explorer | Confirmed | In CISA | 25 Feb 2022 |
|
CVE-2017-8570
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code... |
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, and Microsoft Office 2016. | Confirmed | In CISA | 25 Feb 2022 |
|
CVE-2017-0001
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server... |
Windows GDI | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-0261
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle... |
Microsoft Office | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-11826
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word... |
Microsoft Office | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-8540
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1,... |
Malware Protection Engine | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-0101
The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows... |
Windows | Confirmed | In CISA | 15 Mar 2022 |
|
CVE-2017-0146
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;... |
Windows SMB | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2017-0037
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the... |
Internet Browser | Confirmed | In CISA | 28 Mar 2022 |
|
CVE-2017-0059
Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka... |
Internet Explorer | Confirmed | In CISA | 28 Mar 2022 |
|
CVE-2017-0213
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,... |
Windows COM | Confirmed | In CISA | 28 Mar 2022 |
|
CVE-2017-0148
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;... |
Windows SMB | Confirmed | In CISA | 06 Apr 2022 |
|
CVE-2017-8543
Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8,... |
Microsoft Windows | Confirmed | In CISA | 24 May 2022 |
|
CVE-2017-0210
An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an... |
Internet Explorer | Confirmed | In CISA | 24 May 2022 |
|
CVE-2017-0149
Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a... |
Internet Explorer | Confirmed | In CISA | 24 May 2022 |
|
CVE-2017-0005
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server... |
Windows GDI | Confirmed | In CISA | 24 May 2022 |
|
CVE-2017-0022
Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2... |
XML Core Services | Confirmed | In CISA | 24 May 2022 |
|
CVE-2017-0147
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;... |
Windows SMB | Confirmed | In CISA | 24 May 2022 |
No Microsoft Corporation CVEs match this search or filter.
Showing 30 of 30 Microsoft Corporation known exploited vulnerabilities.
Recurring weakness patterns
Restriction, out-of-bounds write, and use after free account for twelve mapped occurrences across this Microsoft Corporation KEV portfolio.
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
CWE-787
Out-of-bounds Write
CWE-416
Use After Free
CWE-281
Improper Preservation of Permissions
CWE-20
Improper Input Validation
CWE-843
Access of Resource Using Incompatible Type ('Type Confusion')
CWE-94
Improper Control of Generation of Code ('Code Injection')
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.