Microsoft Win32k known exploited vulnerabilities, ranked
CISA lists 25 Microsoft Win32k CVEs as exploited in the wild. 0 were added in the last 12 months and 11 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.
Patch these first
- CVE-2014-4113: EPSS 86.9%, added 2022-05-04
- CVE-2016-7255: EPSS 81.0%, used in ransomware, added 2021-11-03
- CVE-2021-1732: EPSS 78.4%, used in ransomware, added 2021-11-03
- CVE-2019-1458: EPSS 74.3%, used in ransomware, added 2022-01-10
- CVE-2018-8120: EPSS 73.4%, used in ransomware, added 2022-03-15
All 25 Microsoft Win32k CVEs in CISA KEV, by EPSS
| # | CVE | Flaw | EPSS | Ransomware | Added | Federal due |
|---|---|---|---|---|---|---|
| 1 | CVE-2014-4113 | Win32k Privilege Escalation | 86.9% | – | 2022-05-04 | 2022-05-25 |
| 2 | CVE-2016-7255 | Win32k Privilege Escalation | 81.0% | Yes | 2021-11-03 | 2022-05-03 |
| 3 | CVE-2021-1732 | Win32k Privilege Escalation | 78.4% | Yes | 2021-11-03 | 2021-11-17 |
| 4 | CVE-2019-1458 | Win32k Privilege Escalation | 74.3% | Yes | 2022-01-10 | 2022-07-10 |
| 5 | CVE-2018-8120 | Win32k Privilege Escalation | 73.4% | Yes | 2022-03-15 | 2022-04-05 |
| 6 | CVE-2018-8453 | Win32k Privilege Escalation | 70.0% | Yes | 2022-01-21 | 2022-07-21 |
| 7 | CVE-2022-21882 | Win32k Privilege Escalation | 59.2% | Yes | 2022-02-04 | 2022-02-18 |
| 8 | CVE-2015-1701 | Win32k Privilege Escalation | 55.9% | Yes | 2022-03-03 | 2022-03-24 |
| 9 | CVE-2020-1054 | Win32k Privilege Escalation | 54.2% | – | 2021-11-03 | 2022-05-03 |
| 10 | CVE-2019-0808 | Win32k Privilege Escalation | 53.0% | – | 2021-11-03 | 2022-05-03 |
| 11 | CVE-2019-0803 | Win32k Privilege Escalation | 45.0% | Yes | 2021-11-03 | 2022-05-03 |
| 12 | CVE-2023-29336 | Win32K Privilege Escalation | 41.2% | – | 2023-05-09 | 2023-05-30 |
| 13 | CVE-2013-3660 | Win32k Privilege Escalation | 39.3% | – | 2022-03-28 | 2022-04-18 |
| 14 | CVE-2015-2360 | Win32k Privilege Escalation | 14.8% | – | 2022-05-25 | 2022-06-15 |
| 15 | CVE-2016-0165 | Win32k Privilege Escalation | 13.7% | – | 2023-06-22 | 2023-07-13 |
| 16 | CVE-2015-2546 | Win32k Memory Corruption | 10.1% | Yes | 2022-03-15 | 2022-04-05 |
| 17 | CVE-2017-0263 | Win32k Privilege Escalation | 10.0% | – | 2022-02-10 | 2022-08-10 |
| 18 | CVE-2019-1132 | Win32k Privilege Escalation | 9.8% | – | 2022-03-15 | 2022-04-05 |
| 19 | CVE-2021-28310 | Win32k Privilege Escalation | 8.3% | – | 2021-11-03 | 2021-11-17 |
| 20 | CVE-2016-0167 | Win32k Privilege Escalation | 5.7% | Yes | 2021-11-03 | 2022-05-03 |
| 21 | CVE-2019-0859 | Win32k Privilege Escalation | 4.2% | Yes | 2021-11-03 | 2022-05-03 |
| 22 | CVE-2018-8589 | Win32k Privilege Escalation | 3.0% | – | 2022-05-23 | 2022-06-13 |
| 23 | CVE-2019-0797 | Win32k Privilege Escalation | 1.9% | – | 2021-11-03 | 2022-05-03 |
| 24 | CVE-2021-40450 | Win32k Privilege Escalation | 1.6% | – | 2022-04-25 | 2022-05-16 |
| 25 | CVE-2021-41357 | Win32k Privilege Escalation | 1.6% | – | 2022-04-25 | 2022-05-16 |
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint.
Sources: CISA KEV, FIRST EPSS.
More: all Microsoft KEV CVEs · other Microsoft products: SharePoint · Windows · SharePoint Server · Defender · Internet Explorer · Office · Exchange Server · free KEV badge for Microsoft · all vendors