Analyst command view

MSRC Driver CVE Board

Latest-state board for filtered MSRC CVEs from 2020-01-01 to today, tuned for fast triage across module, CWE, release window, exploitation signal, and acknowledgement context.

Live snapshot
Last Sync
2026-05-20T07:39:30Z
Freshness
1 day(s) ago
Refresh Policy
24h baseline + release watch
Storage
Latest snapshot only
Rows In View
50
Current result set after filter and search.
Exploited Flagged
44
Rows with a non-empty exploitation signal.
Distinct CWE
4
Unique weakness classes in this view.
Modules
41
Unique inferred driver or component labels.
Reset
Active filters CWE CWE-415: Double Free Clear filters
Release Month
May 2026
4 CVE | last update 1 day(s) ago
Release 2026-05-12 Patch Tuesday Count 4
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-32170
Windows Rich Text Edit
Exploitation Less Likely
Windows Rich Text Edit Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-05-12 No -
CVE-2026-21530
Windows Rich Text Edit
Exploitation Less Likely
Windows Rich Text Edit Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
CVE-2026-33838
Windows Message Queuing (MSMQ)
Exploitation Less Likely
Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
Anonymous working with TrendAI Zero Day Initiative
CVE-2026-34341
Windows Link-Layer Discovery Protocol (LLDP)
Exploitation Less Likely
Windows Link-Layer Discovery Protocol (LLDP) Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
hazard
Release Month
April 2026
6 CVE | last update 1 day(s) ago
Release 2026-04-14 Patch Tuesday Count 6
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-26166
Windows Shell
Exploitation Less Likely
Windows Shell Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Anonymous
CVE-2026-32074
Windows Projected File System
Exploitation Less Likely
Windows Projected File System Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
ChenJian with Sea Security Orca Team
CVE-2026-32069
Windows Projected File System
Exploitation Less Likely
Windows Projected File System Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
ChenJian with Sea Security Orca Team
CVE-2026-26179
Windows Kernel
Exploitation Less Likely
Windows Kernel Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
fastfail working with TrendAI Zero Day Initiative
CVE-2026-26163
Windows Kernel
Exploitation Less Likely
Windows Kernel Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Samer Karim with Microsoft Inc.
CVE-2026-32219
Microsoft Brokering File System
Exploitation Unlikely
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
hazard
Release Month
January 2026
4 CVE | last update 1 day(s) ago
Release 2026-01-13 Patch Tuesday Count 4
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-20832
Windows Remote Procedure Call Interface Definition Language (IDL)
Exploitation Less Likely
Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-01-13 No
Reported By
Pwnforr777
CVE-2026-20863
Win32k
Exploitation Less Likely
Win32k Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-01-13 No
Reported By
CVE-2026-20867
Windows Management Services
Exploitation Unlikely
Windows Management Services Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-01-13 No
Reported By
Anonymous
CVE-2026-20861
Windows Management Services
Exploitation Less Likely
Windows Management Services Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-01-13 No
Reported By
Anonymous
Release Month
December 2025
1 CVE | last update 1 day(s) ago
Release 2025-12-09 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-62469
Microsoft Brokering File System
Exploitation Unlikely
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-12-09 No
Reported By
hazard
Release Month
November 2025
3 CVE | last update 1 day(s) ago
Release 2025-11-11 Patch Tuesday Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-59505
Windows Smart Card Reader
Exploitation Less Likely
Windows Smart Card Reader Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
Anonymous
CVE-2025-62219
Microsoft Wireless Provisioning System
Exploitation Unlikely
Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
Anonymous
CVE-2025-62215
Windows Kernel
Exploitation Detected
Windows Kernel Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
2025-11-11 Yes
Reported By
Microsoft Threat Intelligence Center (MSTIC) & Microsoft Security Response Center (MSRC)
Release Month
October 2025
2 CVE | last update 1 day(s) ago
Release 2025-10-14 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-59289
Windows Bluetooth Service
Exploitation Less Likely
Windows Bluetooth Service Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-10-14 No
Reported By
Jongseong Kim (nevul37), SEC-agent team with ENKI WhiteHat
Hwiwon Lee (hwiwonl), SEC-agent team
Release 2025-10-01 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2017-5836
The plist_free_data function libplist allows attackers to cause a
No latest release note
The plist_free_data function libplist allows attackers to cause a denial of service
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-10-01 - -
Release Month
September 2025
1 CVE | last update 1 day(s) ago
Release 2025-09-03 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2019-20633
GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a
No latest release note
GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of service via a crafted patch file. NOTE: this issue exists because of an incomplete fix for CVE-2018-6952.
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2025-09-03 - -
Release Month
August 2025
1 CVE | last update 1 day(s) ago
Release 2025-08-12 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-50169
Windows SMB
Exploitation Unlikely
Windows SMB Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-08-12 No
Reported By
Anonymous
Release Month
July 2025
5 CVE | last update 1 day(s) ago
Release 2025-07-08 Patch Tuesday Count 5
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-49667
Windows Win32 Kernel Subsystem
Exploitation Less Likely
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-07-08 No
Reported By
Hussein Alrubaye with Microsoft
CVE-2025-47975
Windows Simple Search and Discovery Protocol (SSDP) Service
Exploitation Less Likely
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-07-08 No
Reported By
CVE-2025-49688
Windows Routing and Remote Access Service (RRAS)
Exploitation Unlikely
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-07-08 No
Reported By
Anonymous
CVE-2025-49693
Microsoft Brokering File System
Exploitation Less Likely
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-07-08 No
Reported By
CVE-2025-49690
Capability Access Management Service (camsvc)
Exploitation Less Likely
Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-07-08 No
Reported By
R4nger with CyberKunLun & Zhiniang Peng with HUST
Pwnforr777
Release Month
April 2025
2 CVE | last update 1 day(s) ago
Release 2025-04-08 Patch Tuesday Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-27730
Windows Digital Media
Exploitation Less Likely
Windows Digital Media Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-04-08 No
Reported By
Jongseong Kim (nevul37) and Dongjun Kim (smlijun) with Ajou University, and working at ENKI WhiteHat
CVE-2025-26640
Windows Digital Media
Exploitation Less Likely
Windows Digital Media Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-04-08 No
Reported By
Anonymous
Release Month
February 2025
3 CVE | last update 1 day(s) ago
Release 2025-02-11 Patch Tuesday Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-21201
Windows Telephony Server
Exploitation Less Likely
Windows Telephony Server Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-02-11 No
Reported By
Anonymous
CVE-2025-21183
Windows Resilient File System (ReFS) Deduplication Service
Exploitation Less Likely
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-02-11 No
CVE-2025-21182
Windows Resilient File System (ReFS) Deduplication Service
Exploitation Less Likely
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-02-11 No
Release Month
January 2025
1 CVE | last update 1 day(s) ago
Release 2025-01-14 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-21291
Windows Direct Show
Exploitation Less Likely
Windows Direct Show Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-01-14 No
Reported By
Mozilla
Release Month
December 2024
1 CVE | last update 1 day(s) ago
Release 2024-12-10 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-49095
Windows PrintWorkflowUserSvc
Exploitation Less Likely
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2024-12-10 No
Release Month
November 2024
2 CVE | last update 1 day(s) ago
Release 2024-11-12 Patch Tuesday Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-43447
Windows SMBv3 Server
Exploitation Less Likely
Windows SMBv3 Server Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2024-11-12 No
Reported By
Anonymous
CVE-2024-43640
Windows Kernel-Mode Driver
Exploitation Less Likely
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2024-11-12 No
Reported By
Kam Reypour
Release Month
October 2024
1 CVE | last update 1 day(s) ago
Release 2024-10-08 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-43514
Windows Resilient File System (ReFS)
Exploitation Less Likely
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2024-10-08 No
Reported By
Anonymous
Release Month
September 2024
1 CVE | last update 1 day(s) ago
Release 2024-09-10 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-38247
Windows Graphics Component
Exploitation More Likely
Windows Graphics Component Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2024-09-10 No
Reported By
Christopher Leung
Release Month
July 2024
1 CVE | last update 1 day(s) ago
Release 2024-07-09 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-30013
Windows MultiPoint Services
Exploitation Less Likely
Windows MultiPoint Services Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2024-07-09 No
Reported By
Release Month
June 2024
1 CVE | last update 1 day(s) ago
Release 2024-06-11 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-30097
Microsoft Speech Application Programming Interface (SAPI)
Exploitation Less Likely
Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2024-06-11 No -
Release Month
May 2024
1 CVE | last update 1 day(s) ago
Release 2024-05-14 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-30027
NTFS
Exploitation Less Likely
NTFS Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2024-05-14 No
Reported By
Anonymous
Release Month
March 2024
1 CVE | last update 1 day(s) ago
Release 2024-03-12 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-21445
Windows USB Print Driver
Exploitation Less Likely
Windows USB Print Driver Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2024-03-12 No
Release Month
September 2023
1 CVE | last update 1 day(s) ago
Release 2023-09-05 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2022-0699
A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an attacker to cause a
No latest release note
A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an attacker to cause a denial of service or have other unspecified impact via control over malloc.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
2023-09-05 - -
Release Month
June 2023
3 CVE | last update 1 day(s) ago
Release 2023-06-28 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-3312
A vulnerability was found in drivers/cpufreq/qcom-cpufreq-hw.c in cpufreq subsystem in the Linux Kernel. This flaw during device unbind will lead to double release problem leading to
No latest release note
A vulnerability was found in drivers/cpufreq/qcom-cpufreq-hw.c in cpufreq subsystem in the Linux Kernel. This flaw during device unbind will lead to double release problem leading to denial of service.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2023-06-28 - -
Release 2023-06-13 Patch Tuesday Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-29366
Windows Geolocation Service
Exploitation Less Likely
Windows Geolocation Service Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-06-13 No
Reported By
kap0k
CVE-2023-29368
Windows Filtering Platform
Exploitation Less Likely
Windows Filtering Platform Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-06-13 No
Reported By
ziming zhang with Ant Security Light-Year Lab
Release Month
May 2023
1 CVE | last update 1 day(s) ago
Release 2023-05-09 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-24903
Windows Secure Socket Tunneling Protocol (SSTP)
Exploitation Less Likely
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-05-09 No
Reported By
Release Month
March 2023
1 CVE | last update 1 day(s) ago
Release 2023-03-14 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-23402
Windows Media
Exploitation Less Likely
Windows Media Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-03-14 No
Release Month
January 2021
1 CVE | last update 1 day(s) ago
Release 2021-01-29 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2020-36225
A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing resulting in
No latest release note
A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing resulting in denial of service.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2021-01-29 - -
Release Month
October 2020
1 CVE | last update 1 day(s) ago
Release 2020-10-09 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2020-25637
A double free memory issue was found to occur in the libvirt API in versions before 6.8.0 responsible for requesting information about network interfaces of a running QEMU domain. This flaw affects the polkit access control driver. Specifically clients connecting to the read-write socket with limited ACL permissions could use this flaw to crash the libvirt daemon resulting in a
No latest release note
A double free memory issue was found to occur in the libvirt API in versions before 6.8.0 responsible for requesting information about network interfaces of a running QEMU domain. This flaw affects the polkit access control driver. Specifically clients connecting to the read-write socket with limited ACL permissions could use this flaw to crash the libvirt daemon resulting in a denial of service or potentially escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVSS vector: AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
2020-10-09 - -