Microsoft Windows known exploited vulnerabilities, ranked
CISA lists 172 Microsoft Windows CVEs as exploited in the wild. 22 were added in the last 12 months and 48 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.
Patch these first
- CVE-2025-59287: EPSS 99.98%, added 2025-10-24
- CVE-2021-34527: EPSS 99.79%, used in ransomware, added 2021-11-03
- CVE-2024-21412: EPSS 99.41%, used in ransomware, added 2024-02-13
- CVE-2022-30190: EPSS 99.16%, used in ransomware, added 2022-06-14
- CVE-2023-36884: EPSS 98.9%, used in ransomware, added 2023-07-17
All 172 Microsoft Windows CVEs in CISA KEV, by EPSS
| # | CVE | Flaw | EPSS | Ransomware | Added | Federal due |
|---|---|---|---|---|---|---|
| 1 | CVE-2025-59287 | Windows Server Update Service (WSUS) Deserialization of Untrusted Data | 99.98% | – | 2025-10-24 | 2025-11-14 |
| 2 | CVE-2021-34527 | Windows Print Spooler Remote Code Execution | 99.79% | Yes | 2021-11-03 | 2022-05-03 |
| 3 | CVE-2024-21412 | Windows Internet Shortcut Files Security Feature Bypass | 99.41% | Yes | 2024-02-13 | 2024-03-05 |
| 4 | CVE-2022-30190 | Windows Support Diagnostic Tool (MSDT) Remote Code Execution | 99.16% | Yes | 2022-06-14 | 2022-07-05 |
| 5 | CVE-2023-36884 | Windows Search Remote Code Execution | 98.9% | Yes | 2023-07-17 | 2023-08-29 |
| 6 | CVE-2008-4250 | Windows Buffer Overflow | 98.8% | – | 2026-05-20 | 2026-06-03 |
| 7 | CVE-2020-1350 | Windows DNS Server Remote Code Execution | 96.7% | – | 2021-11-03 | 2022-05-03 |
| 8 | CVE-2014-6332 | Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution | 94.9% | – | 2022-03-25 | 2022-04-15 |
| 9 | CVE-2017-0143 | Windows Server Message Block (SMBv1) Remote Code Execution | 93.3% | Yes | 2021-11-03 | 2022-05-03 |
| 10 | CVE-2010-2568 | Windows Remote Code Execution | 91.3% | – | 2022-09-15 | 2022-10-06 |
| 11 | CVE-2017-8464 | Windows Shell (.lnk) Remote Code Execution | 89.9% | – | 2022-02-10 | 2022-08-10 |
| 12 | CVE-2017-0146 | Windows SMB Remote Code Execution | 89.9% | Yes | 2022-03-25 | 2022-04-15 |
| 13 | CVE-2020-0601 | Windows CryptoAPI Spoofing | 89.4% | – | 2021-11-03 | 2022-05-03 |
| 14 | CVE-2018-8174 | Windows VBScript Engine Out-of-Bounds Write | 88.3% | Yes | 2022-02-15 | 2022-08-15 |
| 15 | CVE-2023-36025 | Windows SmartScreen Security Feature Bypass | 88.1% | – | 2023-11-14 | 2023-12-05 |
| 16 | CVE-2012-0151 | Windows Authenticode Signature Verification Remote Code Execution | 87.7% | – | 2022-06-08 | 2022-06-22 |
| 17 | CVE-2025-33053 | Windows External Control of File Name or Path | 87.0% | – | 2025-06-10 | 2025-07-01 |
| 18 | CVE-2015-2426 | Windows Adobe Type Manager Library Remote Code Execution | 86.6% | – | 2022-03-28 | 2022-04-18 |
| 19 | CVE-2021-1675 | Windows Print Spooler Remote Code Execution | 85.3% | Yes | 2021-11-03 | 2021-11-17 |
| 20 | CVE-2024-38112 | Windows MSHTML Platform Spoofing | 84.2% | – | 2024-07-09 | 2024-07-30 |
| 21 | CVE-2017-0213 | Windows Privilege Escalation | 84.1% | Yes | 2022-03-28 | 2022-04-18 |
| 22 | CVE-2024-43451 | Windows NTLMv2 Hash Disclosure Spoofing | 84.1% | – | 2024-11-12 | 2024-12-03 |
| 23 | CVE-2025-33073 | Windows SMB Client Improper Access Control | 82.7% | – | 2025-10-20 | 2025-11-10 |
| 24 | CVE-2014-4114 | Windows Object Linking & Embedding (OLE) Remote Code Execution | 81.6% | – | 2022-03-03 | 2022-03-24 |
| 25 | CVE-2021-31955 | Windows Kernel Information Disclosure | 81.1% | – | 2021-11-03 | 2021-11-17 |
| 26 | CVE-2011-3402 | Windows Remote Code Execution | 78.1% | – | 2025-10-06 | 2025-10-27 |
| 27 | CVE-2023-24880 | Windows SmartScreen Security Feature Bypass | 78.0% | Yes | 2023-03-14 | 2023-04-04 |
| 28 | CVE-2014-6352 | Windows Code Injection | 77.5% | – | 2022-02-25 | 2022-08-25 |
| 29 | CVE-2008-0015 | Windows Video ActiveX Control Remote Code Execution | 76.6% | – | 2026-02-17 | 2026-03-10 |
| 30 | CVE-2015-0016 | Windows TS WebProxy Directory Traversal | 75.8% | – | 2022-05-25 | 2022-06-15 |
| 31 | CVE-2017-8543 | Windows Search Remote Code Execution | 74.2% | – | 2022-05-24 | 2022-06-14 |
| 32 | CVE-2021-40449 | Windows Win32k Privilege Escalation | 74.1% | Yes | 2021-11-17 | 2021-12-01 |
| 33 | CVE-2013-3918 | Windows Out-of-Bounds Write | 73.7% | – | 2025-10-06 | 2025-10-27 |
| 34 | CVE-2018-0824 | COM for Windows Deserialization of Untrusted Data | 73.2% | – | 2024-08-05 | 2024-08-26 |
| 35 | CVE-2018-8414 | Windows Shell Remote Code Execution | 72.9% | – | 2022-03-25 | 2022-04-15 |
| 36 | CVE-2016-0185 | Windows Media Center Remote Code Execution | 69.8% | – | 2021-11-03 | 2022-05-03 |
| 37 | CVE-2020-0938 | Windows Adobe Font Manager Library Remote Code Execution | 69.0% | – | 2021-11-03 | 2022-05-03 |
| 38 | CVE-2016-3393 | Windows Graphics Device Interface (GDI) Remote Code Execution | 68.5% | – | 2022-05-25 | 2022-06-15 |
| 39 | CVE-2022-34713 | Windows Support Diagnostic Tool (MSDT) Remote Code Execution | 67.8% | – | 2022-08-09 | 2022-08-30 |
| 40 | CVE-2021-36934 | Windows SAM Local Privilege Escalation | 67.3% | – | 2022-02-10 | 2022-02-24 |
| 41 | CVE-2024-43572 | Windows Management Console Remote Code Execution | 66.7% | – | 2024-10-08 | 2024-10-29 |
| 42 | CVE-2021-36942 | Windows Local Security Authority (LSA) Spoofing | 66.0% | Yes | 2021-11-03 | 2021-11-17 |
| 43 | CVE-2020-1020 | Windows Adobe Font Manager Library Remote Code Execution | 65.0% | – | 2021-11-03 | 2022-05-03 |
| 44 | CVE-2014-1812 | Windows Group Policy Preferences Password Privilege Escalation | 64.9% | Yes | 2021-11-03 | 2022-05-03 |
| 45 | CVE-2016-7256 | Windows Open Type Font Remote Code Execution | 64.6% | – | 2022-05-25 | 2022-06-15 |
| 46 | CVE-2014-4148 | Windows Remote Code Execution | 59.9% | – | 2022-05-25 | 2022-06-15 |
| 47 | CVE-2024-21338 | Windows Kernel Exposed IOCTL with Insufficient Access Control | 59.8% | Yes | 2024-03-04 | 2024-03-25 |
| 48 | CVE-2021-33742 | Windows MSHTML Platform Remote Code Execution | 59.4% | – | 2021-11-03 | 2021-11-17 |
| 49 | CVE-2025-24054 | Windows NTLM Hash Disclosure Spoofing | 58.9% | – | 2025-04-17 | 2025-05-08 |
| 50 | CVE-2017-0101 | Windows Transaction Manager Privilege Escalation | 57.5% | Yes | 2022-03-15 | 2022-04-05 |
| 51 | CVE-2024-43461 | Windows MSHTML Platform Spoofing | 54.5% | – | 2024-09-16 | 2024-10-07 |
| 52 | CVE-2022-21971 | Windows Runtime Remote Code Execution | 53.9% | – | 2022-08-18 | 2022-09-08 |
| 53 | CVE-2015-1671 | Windows Remote Code Execution | 49.0% | – | 2022-05-25 | 2022-06-15 |
| 54 | CVE-2023-28252 | Windows Common Log File System (CLFS) Driver Privilege Escalation | 49.0% | Yes | 2023-04-11 | 2023-05-02 |
| 55 | CVE-2024-43573 | Windows MSHTML Platform Spoofing | 46.1% | – | 2024-10-08 | 2024-10-29 |
| 56 | CVE-2023-36874 | Windows Error Reporting Service Privilege Escalation | 42.6% | – | 2023-07-11 | 2023-08-01 |
| 57 | CVE-2020-0787 | Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management | 42.5% | Yes | 2022-01-28 | 2022-07-28 |
| 58 | CVE-2019-0841 | Windows AppX Deployment Service (AppXSVC) Privilege Escalation | 41.4% | Yes | 2022-03-15 | 2022-04-05 |
| 59 | CVE-2024-38178 | Windows Scripting Engine Memory Corruption | 41.4% | – | 2024-08-13 | 2024-09-03 |
| 60 | CVE-2022-21999 | Windows Print Spooler Privilege Escalation | 41.0% | Yes | 2022-03-25 | 2022-04-15 |
| 61 | CVE-2023-21674 | Windows Advanced Local Procedure Call (ALPC) Privilege Escalation | 41.0% | – | 2023-01-10 | 2023-01-31 |
| 62 | CVE-2021-34448 | Windows Scripting Engine Memory Corruption | 40.1% | – | 2021-11-03 | 2021-11-17 |
| 63 | CVE-2020-1464 | Windows Spoofing | 38.9% | – | 2021-11-03 | 2022-05-03 |
| 64 | CVE-2016-0099 | Windows Secondary Logon Service Privilege Escalation | 37.0% | Yes | 2022-03-03 | 2022-03-24 |
| 65 | CVE-2013-5065 | Windows Kernel Privilege Escalation | 34.7% | – | 2022-03-03 | 2022-03-24 |
| 66 | CVE-2025-26633 | Windows Management Console (MMC) Improper Neutralization | 30.4% | Yes | 2025-03-11 | 2025-04-01 |
| 67 | CVE-2019-1405 | Windows Universal Plug and Play (UPnP) Service Privilege Escalation | 29.9% | Yes | 2022-03-15 | 2022-04-05 |
| 68 | CVE-2024-38193 | Windows Ancillary Function Driver for WinSock Privilege Escalation | 28.7% | – | 2024-08-13 | 2024-09-03 |
| 69 | CVE-2010-0232 | Windows Kernel Exception Handler | 28.7% | – | 2022-03-03 | 2022-03-24 |
| 70 | CVE-2022-37969 | Windows Common Log File System (CLFS) Driver Privilege Escalation | 28.3% | Yes | 2022-09-14 | 2022-10-05 |
| 71 | CVE-2024-21351 | Windows SmartScreen Security Feature Bypass | 27.8% | – | 2024-02-13 | 2024-03-05 |
| 72 | CVE-2025-30397 | Windows Scripting Engine Type Confusion | 26.8% | – | 2025-05-13 | 2025-06-03 |
| 73 | CVE-2024-49138 | Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow | 26.2% | – | 2024-12-10 | 2024-12-31 |
| 74 | CVE-2024-35250 | Windows Kernel-Mode Driver Untrusted Pointer Dereference | 25.2% | – | 2024-12-16 | 2025-01-06 |
| 75 | CVE-2022-41128 | Windows Scripting Languages Remote Code Execution | 24.6% | – | 2022-11-08 | 2022-12-09 |
| 76 | CVE-2016-0040 | Windows Kernel Privilege Escalation | 24.5% | – | 2022-03-28 | 2022-04-18 |
| 77 | CVE-2026-21510 | Windows Shell Protection Mechanism Failure | 24.2% | – | 2026-02-10 | 2026-03-03 |
| 78 | CVE-2021-36948 | Windows Update Medic Service Privilege Escalation | 23.3% | – | 2021-11-03 | 2021-11-17 |
| 79 | CVE-2021-31956 | Windows NTFS Privilege Escalation | 22.3% | – | 2021-11-03 | 2021-11-17 |
| 80 | CVE-2018-8639 | Windows Win32k Improper Resource Shutdown or Release | 22.2% | Yes | 2025-03-03 | 2025-03-24 |
| 81 | CVE-2021-34484 | Windows User Profile Service Privilege Escalation | 21.8% | – | 2022-03-31 | 2022-04-21 |
| 82 | CVE-2016-3309 | Windows Kernel Privilege Escalation | 20.5% | Yes | 2022-03-15 | 2022-04-05 |
| 83 | CVE-2021-41379 | Windows Installer Privilege Escalation | 19.5% | Yes | 2022-03-03 | 2022-03-17 |
| 84 | CVE-2019-1215 | Windows Privilege Escalation | 19.3% | Yes | 2021-11-03 | 2022-05-03 |
| 85 | CVE-2019-1322 | Windows Privilege Escalation | 19.2% | Yes | 2022-03-15 | 2022-04-05 |
| 86 | CVE-2022-22047 | Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation | 18.8% | – | 2022-07-12 | 2022-08-02 |
| 87 | CVE-2022-22718 | Windows Print Spooler Privilege Escalation | 18.5% | – | 2022-04-19 | 2022-05-10 |
| 88 | CVE-2018-8440 | Windows Privilege Escalation | 18.4% | Yes | 2022-03-28 | 2022-04-18 |
| 89 | CVE-2022-26904 | Windows User Profile Service Privilege Escalation | 16.9% | – | 2022-04-25 | 2022-05-16 |
| 90 | CVE-2023-36036 | Windows Cloud Files Mini Filter Driver Privilege Escalation | 16.7% | – | 2023-11-14 | 2023-12-05 |
| 91 | CVE-2020-0986 | Windows Kernel Privilege Escalation | 16.3% | – | 2021-11-03 | 2022-05-03 |
| 92 | CVE-2026-21513 | MSHTML Framework Protection Mechanism Failure | 15.6% | – | 2026-02-10 | 2026-03-03 |
| 93 | CVE-2022-38028 | Windows Print Spooler Privilege Escalation | 14.9% | – | 2024-04-23 | 2024-05-14 |
| 94 | CVE-2024-49039 | Windows Task Scheduler Privilege Escalation | 14.2% | Yes | 2024-11-12 | 2024-12-03 |
| 95 | CVE-2025-29824 | Windows Common Log File System (CLFS) Driver Use-After-Free | 13.9% | Yes | 2025-04-08 | 2025-04-29 |
| 96 | CVE-2024-38213 | Windows SmartScreen Security Feature Bypass | 13.6% | – | 2024-08-13 | 2024-09-03 |
| 97 | CVE-2023-36424 | Windows Out-of-Bounds Read | 12.2% | – | 2026-04-13 | 2026-04-27 |
| 98 | CVE-2023-36033 | Windows Desktop Window Manager (DWM) Core Library Privilege Escalation | 12.0% | – | 2023-11-14 | 2023-12-05 |
| 99 | CVE-2019-1253 | Windows AppX Deployment Server Privilege Escalation | 11.6% | Yes | 2022-03-15 | 2022-04-05 |
| 100 | CVE-2017-0005 | Windows Graphics Device Interface (GDI) Privilege Escalation | 11.0% | – | 2022-05-24 | 2022-06-14 |
| 101 | CVE-2023-23376 | Windows Common Log File System (CLFS) Driver Privilege Escalation | 10.9% | Yes | 2023-02-14 | 2023-03-07 |
| 102 | CVE-2022-26925 | Windows LSA Spoofing | 10.5% | – | 2022-07-01 | 2022-07-22 |
| 103 | CVE-2021-43890 | Windows AppX Installer Spoofing | 10.3% | Yes | 2021-12-15 | 2021-12-29 |
| 104 | CVE-2021-33771 | Windows Kernel Privilege Escalation | 10.2% | – | 2021-11-03 | 2021-11-17 |
| 105 | CVE-2023-32046 | Windows MSHTML Platform Privilege Escalation | 10.0% | – | 2023-07-11 | 2023-08-01 |
| 106 | CVE-2024-38217 | Windows Mark of the Web (MOTW) Protection Mechanism Failure | 10.0% | – | 2024-09-10 | 2024-10-01 |
| 107 | CVE-2025-21333 | Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow | 10.0% | – | 2025-01-14 | 2025-02-04 |
| 108 | CVE-2019-0703 | Windows SMB Information Disclosure | 9.6% | – | 2022-05-23 | 2022-06-13 |
| 109 | CVE-2021-34486 | Windows Event Tracing Privilege Escalation | 9.3% | – | 2022-03-28 | 2022-04-18 |
| 110 | CVE-2010-4398 | Windows Kernel Stack-Based Buffer Overflow | 8.7% | – | 2022-03-28 | 2022-04-21 |
| 111 | CVE-2019-1388 | Windows Certificate Dialog Privilege Escalation | 8.6% | Yes | 2023-04-07 | 2023-04-28 |
| 112 | CVE-2020-0683 | Windows Installer Privilege Escalation | 7.6% | – | 2021-11-03 | 2022-05-03 |
| 113 | CVE-2004-0210 | Windows Privilege Escalation | 7.2% | – | 2022-03-03 | 2022-03-24 |
| 114 | CVE-2026-20805 | Windows Information Disclosure | 7.2% | – | 2026-01-13 | 2026-02-03 |
| 115 | CVE-2022-24521 | Windows CLFS Driver Privilege Escalation | 7.1% | Yes | 2022-04-13 | 2022-05-04 |
| 116 | CVE-2019-1064 | Windows AppX Deployment Service (AppXSVC) Privilege Escalation | 6.9% | Yes | 2022-03-15 | 2022-04-05 |
| 117 | CVE-2021-33739 | Desktop Window Manager (DWM) Core Library Privilege Escalation | 6.6% | – | 2021-11-03 | 2021-11-17 |
| 118 | CVE-2025-24990 | Windows Untrusted Pointer Dereference | 6.4% | – | 2025-10-14 | 2025-11-04 |
| 119 | CVE-2024-38106 | Windows Kernel Privilege Escalation | 6.3% | – | 2024-08-13 | 2024-09-03 |
| 120 | CVE-2024-38014 | Windows Installer Improper Privilege Management | 6.3% | – | 2024-09-10 | 2024-10-01 |
| 121 | CVE-2025-62215 | Windows Race Condition | 6.0% | – | 2025-11-12 | 2025-12-03 |
| 122 | CVE-2023-21823 | Windows Graphic Component Privilege Escalation | 5.6% | – | 2023-02-14 | 2023-03-07 |
| 123 | CVE-2020-17087 | Windows Kernel Privilege Escalation | 5.4% | – | 2021-11-03 | 2022-05-03 |
| 124 | CVE-2019-0863 | Windows Error Reporting (WER) Privilege Escalation | 5.2% | – | 2021-11-03 | 2022-05-03 |
| 125 | CVE-2015-6175 | Windows Kernel Privilege Escalation | 5.1% | – | 2022-05-25 | 2022-06-15 |
| 126 | CVE-2002-0367 | Windows Privilege Escalation | 4.9% | – | 2022-03-03 | 2022-03-24 |
| 127 | CVE-2026-32202 | Windows Protection Mechanism Failure | 4.9% | – | 2026-04-28 | 2026-05-12 |
| 128 | CVE-2009-1123 | Windows Improper Input Validation | 4.9% | – | 2022-03-03 | 2022-03-24 |
| 129 | CVE-2026-21525 | Windows NULL Pointer Dereference | 4.8% | – | 2026-02-10 | 2026-03-03 |
| 130 | CVE-2019-0543 | Windows Privilege Escalation | 4.7% | Yes | 2022-03-15 | 2022-04-05 |
| 131 | CVE-2025-60710 | Windows Link Following | 4.6% | Yes | 2026-04-13 | 2026-04-27 |
| 132 | CVE-2020-1027 | Windows Kernel Privilege Escalation | 4.5% | – | 2022-05-23 | 2022-06-13 |
| 133 | CVE-2021-31979 | Windows Kernel Privilege Escalation | 4.5% | – | 2021-11-03 | 2021-11-17 |
| 134 | CVE-2018-8611 | Windows Kernel Privilege Escalation | 4.2% | – | 2022-05-24 | 2022-06-14 |
| 135 | CVE-2023-32049 | Windows Defender SmartScreen Security Feature Bypass | 4.2% | – | 2023-07-11 | 2023-08-01 |
| 136 | CVE-2026-21533 | Windows Improper Privilege Management | 4.1% | – | 2026-02-10 | 2026-03-03 |
| 137 | CVE-2015-1769 | Windows Mount Manager Privilege Escalation | 4.1% | – | 2022-05-25 | 2022-06-15 |
| 138 | CVE-2021-36955 | Windows Common Log File System (CLFS) Driver Privilege Escalation | 4.0% | Yes | 2021-11-03 | 2021-11-17 |
| 139 | CVE-2024-26169 | Windows Error Reporting Service Improper Privilege Management | 4.0% | Yes | 2024-06-13 | 2024-07-04 |
| 140 | CVE-2024-30040 | Windows MSHTML Platform Security Feature Bypass | 3.9% | – | 2024-05-14 | 2024-06-04 |
| 141 | CVE-2025-24985 | Windows Fast FAT File System Driver Integer Overflow | 3.8% | – | 2025-03-11 | 2025-04-01 |
| 142 | CVE-2026-85880 | Windows Heap-Based Buffer Overflow | 3.6% | – | 2026-09-08 | 2026-09-22 |
| 143 | CVE-2019-1385 | Windows AppX Deployment Extensions Privilege Escalation | 3.6% | Yes | 2022-05-23 | 2022-06-13 |
| 144 | CVE-2019-1315 | Windows Error Reporting Manager Privilege Escalation | 3.5% | Yes | 2022-03-15 | 2022-04-05 |
| 145 | CVE-2021-43226 | Windows Privilege Escalation | 3.1% | Yes | 2025-10-06 | 2025-10-27 |
| 146 | CVE-2023-36584 | Windows Mark of the Web (MOTW) Security Feature Bypass | 3.1% | – | 2023-11-16 | 2023-12-07 |
| 147 | CVE-2022-41125 | Windows CNG Key Isolation Service Privilege Escalation | 3.0% | – | 2022-11-08 | 2022-12-09 |
| 148 | CVE-2025-59230 | Windows Improper Access Control | 2.7% | – | 2025-10-14 | 2025-11-04 |
| 149 | CVE-2025-62221 | Windows Use After Free | 2.5% | – | 2025-12-09 | 2025-12-30 |
| 150 | CVE-2022-41049 | Windows Mark of the Web (MOTW) Security Feature Bypass | 2.5% | – | 2022-11-14 | 2022-12-09 |
| 151 | CVE-2026-21519 | Windows Type Confusion | 2.5% | – | 2026-02-10 | 2026-03-03 |
| 152 | CVE-2022-21919 | Windows User Profile Service Privilege Escalation | 2.4% | – | 2022-04-25 | 2022-05-16 |
| 153 | CVE-2025-32706 | Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow | 2.3% | – | 2025-05-13 | 2025-06-03 |
| 154 | CVE-2025-21391 | Windows Storage Link Following | 2.3% | – | 2025-02-11 | 2025-03-04 |
| 155 | CVE-2019-0880 | Windows Privilege Escalation | 2.3% | – | 2022-05-23 | 2022-06-13 |
| 156 | CVE-2022-41073 | Windows Print Spooler Privilege Escalation | 2.3% | Yes | 2022-11-08 | 2022-12-09 |
| 157 | CVE-2025-24993 | Windows NTFS Heap-Based Buffer Overflow | 2.2% | – | 2025-03-11 | 2025-04-01 |
| 158 | CVE-2025-32709 | Windows Ancillary Function Driver for WinSock Use-After-Free | 2.2% | – | 2025-05-13 | 2025-06-03 |
| 159 | CVE-2025-24991 | Windows NTFS Out-Of-Bounds Read | 2.0% | – | 2025-03-11 | 2025-04-01 |
| 160 | CVE-2025-24984 | Windows NTFS Information Disclosure | 2.0% | – | 2025-03-11 | 2025-04-01 |
| 161 | CVE-2025-30400 | Windows DWM Core Library Use-After-Free | 1.9% | – | 2025-05-13 | 2025-06-03 |
| 162 | CVE-2022-41091 | Windows Mark of the Web (MOTW) Security Feature Bypass | 1.8% | Yes | 2022-11-08 | 2022-12-09 |
| 163 | CVE-2019-1129 | Windows AppX Deployment Service (AppXSVC) Privilege Escalation | 1.8% | Yes | 2022-03-15 | 2022-04-05 |
| 164 | CVE-2019-1130 | Windows AppX Deployment Service Privilege Escalation | 1.7% | Yes | 2022-05-23 | 2022-06-13 |
| 165 | CVE-2024-38107 | Windows Power Dependency Coordinator Privilege Escalation | 1.6% | – | 2024-08-13 | 2024-09-03 |
| 166 | CVE-2025-21418 | Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow | 1.6% | – | 2025-02-11 | 2025-03-04 |
| 167 | CVE-2025-21334 | Windows Hyper-V NT Kernel Integration VSP Use-After-Free | 1.6% | – | 2025-01-14 | 2025-02-04 |
| 168 | CVE-2019-1214 | Windows Privilege Common Log File System (CLFS) Escalation | 1.4% | – | 2021-11-03 | 2022-05-03 |
| 169 | CVE-2025-32701 | Windows Common Log File System (CLFS) Driver Use-After-Free | 1.4% | – | 2025-05-13 | 2025-06-03 |
| 170 | CVE-2025-21335 | Windows Hyper-V NT Kernel Integration VSP Use-After-Free | 1.4% | – | 2025-01-14 | 2025-02-04 |
| 171 | CVE-2025-24983 | Windows Win32k Use-After-Free | 1.3% | – | 2025-03-11 | 2025-04-01 |
| 172 | CVE-2026-81963 | Windows Link Following | 0.4% | – | 2026-09-08 | 2026-09-22 |
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint.
Sources: CISA KEV, FIRST EPSS.
More: all Microsoft KEV CVEs · other Microsoft products: SharePoint · SharePoint Server · Defender · Internet Explorer · Office · Exchange Server · Win32k · free KEV badge for Microsoft · all vendors