Microsoft Corporation vendor intelligence

Microsoft Corporation Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Microsoft Corporation products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Total KEVs
30
Known exploited vulnerabilities affecting Microsoft Corporation products
In CISA KEV
30
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited CVEs absent from CISA KEV
Sensor Observed
0
Microsoft Corporation KEVs with sensor-observed exploitation activity

The catalog gap matters for Microsoft Corporation exposure

All 30 exploited Microsoft Corporation CVEs tracked here are also listed in CISA KEV. Use product ownership and sensor evidence to prioritize within this portfolio.

100%
Covered by CISA
0%
Beyond CISA
16
Product families

Attested Microsoft Corporation CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2017-11774

Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft...

Microsoft Outlook Confirmed In CISA 03 Nov 2021
CVE-2017-0199

Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server...

Office/WordPad Confirmed In CISA 03 Nov 2021
CVE-2017-11882

Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow...

Microsoft Office Confirmed In CISA 03 Nov 2021
CVE-2018-0802

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution...

Equation Editor Confirmed In CISA 03 Nov 2021
CVE-2018-0798

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution...

Equation Editor Confirmed In CISA 03 Nov 2021
CVE-2017-8759

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or...

Microsoft .NET Framework Confirmed In CISA 03 Nov 2021
CVE-2017-0143

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;...

Windows SMB Confirmed In CISA 03 Nov 2021
CVE-2017-0144

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;...

Windows SMB Confirmed In CISA 10 Feb 2022
CVE-2017-0145

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;...

Windows SMB Confirmed In CISA 10 Feb 2022
CVE-2017-0262

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle...

Microsoft Office Confirmed In CISA 10 Feb 2022
CVE-2017-0263

The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT...

Microsoft Windows Confirmed In CISA 10 Feb 2022
CVE-2017-8464

Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT...

Windows Shell Confirmed In CISA 10 Feb 2022
CVE-2017-0222

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption...

Internet Explorer Confirmed In CISA 25 Feb 2022
CVE-2017-8570

Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code...

Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, and Microsoft Office 2016. Confirmed In CISA 25 Feb 2022
CVE-2017-0001

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server...

Windows GDI Confirmed In CISA 03 Mar 2022
CVE-2017-0261

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle...

Microsoft Office Confirmed In CISA 03 Mar 2022
CVE-2017-11826

Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word...

Microsoft Office Confirmed In CISA 03 Mar 2022
CVE-2017-8540

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1,...

Malware Protection Engine Confirmed In CISA 03 Mar 2022
CVE-2017-0101

The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows...

Windows Confirmed In CISA 15 Mar 2022
CVE-2017-0146

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;...

Windows SMB Confirmed In CISA 25 Mar 2022
CVE-2017-0037

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the...

Internet Browser Confirmed In CISA 28 Mar 2022
CVE-2017-0059

Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka...

Internet Explorer Confirmed In CISA 28 Mar 2022
CVE-2017-0213

Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,...

Windows COM Confirmed In CISA 28 Mar 2022
CVE-2017-0148

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;...

Windows SMB Confirmed In CISA 06 Apr 2022
CVE-2017-8543

Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8,...

Microsoft Windows Confirmed In CISA 24 May 2022
CVE-2017-0210

An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an...

Internet Explorer Confirmed In CISA 24 May 2022
CVE-2017-0149

Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a...

Internet Explorer Confirmed In CISA 24 May 2022
CVE-2017-0005

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server...

Windows GDI Confirmed In CISA 24 May 2022
CVE-2017-0022

Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2...

XML Core Services Confirmed In CISA 24 May 2022
CVE-2017-0147

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;...

Windows SMB Confirmed In CISA 24 May 2022

Showing 30 of 30 Microsoft Corporation known exploited vulnerabilities.

Recurring weakness patterns

Restriction, out-of-bounds write, and use after free account for twelve mapped occurrences across this Microsoft Corporation KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.