CyberMax
Home › Exploited CVEs › Microsoft

Microsoft Win32k known exploited vulnerabilities, ranked

CISA KEV catalog 2026.10.02 · FIRST EPSS scores from 2026-10-02

CISA lists 25 Microsoft Win32k CVEs as exploited in the wild. 0 were added in the last 12 months and 11 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.

Patch these first

All 25 Microsoft Win32k CVEs in CISA KEV, by EPSS

#CVEFlawEPSSRansomwareAddedFederal due
1CVE-2014-4113Win32k Privilege Escalation86.9%–2022-05-042022-05-25
2CVE-2016-7255Win32k Privilege Escalation81.0%Yes2021-11-032022-05-03
3CVE-2021-1732Win32k Privilege Escalation78.4%Yes2021-11-032021-11-17
4CVE-2019-1458Win32k Privilege Escalation74.3%Yes2022-01-102022-07-10
5CVE-2018-8120Win32k Privilege Escalation73.4%Yes2022-03-152022-04-05
6CVE-2018-8453Win32k Privilege Escalation70.0%Yes2022-01-212022-07-21
7CVE-2022-21882Win32k Privilege Escalation59.2%Yes2022-02-042022-02-18
8CVE-2015-1701Win32k Privilege Escalation55.9%Yes2022-03-032022-03-24
9CVE-2020-1054Win32k Privilege Escalation54.2%–2021-11-032022-05-03
10CVE-2019-0808Win32k Privilege Escalation53.0%–2021-11-032022-05-03
11CVE-2019-0803Win32k Privilege Escalation45.0%Yes2021-11-032022-05-03
12CVE-2023-29336Win32K Privilege Escalation41.2%–2023-05-092023-05-30
13CVE-2013-3660Win32k Privilege Escalation39.3%–2022-03-282022-04-18
14CVE-2015-2360Win32k Privilege Escalation14.8%–2022-05-252022-06-15
15CVE-2016-0165Win32k Privilege Escalation13.7%–2023-06-222023-07-13
16CVE-2015-2546Win32k Memory Corruption10.1%Yes2022-03-152022-04-05
17CVE-2017-0263Win32k Privilege Escalation10.0%–2022-02-102022-08-10
18CVE-2019-1132Win32k Privilege Escalation9.8%–2022-03-152022-04-05
19CVE-2021-28310Win32k Privilege Escalation8.3%–2021-11-032021-11-17
20CVE-2016-0167Win32k Privilege Escalation5.7%Yes2021-11-032022-05-03
21CVE-2019-0859Win32k Privilege Escalation4.2%Yes2021-11-032022-05-03
22CVE-2018-8589Win32k Privilege Escalation3.0%–2022-05-232022-06-13
23CVE-2019-0797Win32k Privilege Escalation1.9%–2021-11-032022-05-03
24CVE-2021-40450Win32k Privilege Escalation1.6%–2022-04-252022-05-16
25CVE-2021-41357Win32k Privilege Escalation1.6%–2022-04-252022-05-16
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

More: all Microsoft KEV CVEs · other Microsoft products: SharePoint · Windows · SharePoint Server · Defender · Internet Explorer · Office · Exchange Server · free KEV badge for Microsoft · all vendors