FAIL › dossier
windows
PRODUCT· dossier confidence 40%
Microsoft Windows is a critical software asset with a high volume of actively exploited vulnerabilities in 2026, including ransomware campaigns targeting Windows Defender and multiple critical RCE flaws in the OS and ecosystem.
PROFILE
CategorySoftware VendorWhat they doMicrosoft Corporation develops and supports software, services, devices, and solutions worldwide, including the Windows operating system and Microsoft 365 commercial products.Ownershippublic
Websitehttps://www.microsoft.com ↗
SECURITY POSTURE
Microsoft Windows demonstrates a high volume of actively exploited vulnerabilities, including multiple critical RCE and privilege escalation flaws in 2026, with active exploitation confirmed by CISA and industry forums.
Notable failures
- CVE-2025-60710: Privilege escalation via link-following flaw
- CVE-2026-32202: Network spoofing bypassing authentication
- CVE-2026-13776: Critical sandbox escape in Chrome renderer process
- CVE-2026-33825: BlueHammer ransomware exploitation of Windows Defender
- CVE-2026-45607: Hyper-V Remote Code Execution
- CVE-2026-40404: UDFS Elevation of Privilege
Patterns: Repeated unpatched edge-device RCEs; Active exploitation of privilege escalation flaws; High volume of critical vulnerabilities in 2026
FAILURE HISTORY · 60
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-03-25 | CVE-2017-0146 | critical | A critical Windows vulnerability allowed remote code execution via SMBv1, actively exploited and linked to ransomware attacks, demonstrating a failure to patch a known risk. |
| 2022-02-15 | CVE-2018-8174 | critical | A critical, actively exploited Windows VBScript engine vulnerability allows remote code execution. |
| 2021-11-03 | CVE-2017-0143 | critical | A critical, actively exploited vulnerability in Microsoft's SMBv1 allowed for remote code execution, impacting many DIB systems still running vulnerable Windows versions. |
| 2021-11-03 | CVE-2021-1675 | critical | A critical, actively exploited Windows Print Spooler vulnerability allows for remote code execution. |
| 2023-01-10 | CVE-2023-21674 | high | Microsoft Windows ALPC flaw exploited in wild for privilege escalation |
| 2022-09-14 | CVE-2022-37969 | high | Microsoft Windows CLFS Driver allows unauthorized escalation of privileges |
| 2026-04-13 | CVE-2025-60710 | high | Microsoft Windows is actively exploited for privilege escalation via CVE-2025-60710, a link-following flaw enabling unauthorized admin access. |
| 2025-04-08 | CVE-2025-29824 | critical | A use-after-free vulnerability in the Windows CLFS driver allows local privilege escalation and is actively exploited by ransomware. |
| 2025-03-03 | CVE-2018-8639 | critical | A local, authenticated privilege escalation flaw in Windows Win32k allowed attackers to run arbitrary kernel-mode code, leading to ransomware outbreaks. |
| 2024-11-12 | CVE-2024-49039 | critical | An unpatched privilege escalation flaw in Windows Task Scheduler lets attackers bypass AppContainer restrictions and execute privileged RPC calls. |
| 2024-10-15 | CVE-2024-30088 | critical | A TOCTOU race condition in the Windows kernel allows privilege escalation and is actively exploited in the wild. |
| 2024-06-13 | CVE-2024-26169 | critical | A local privilege escalation flaw in Windows Error Reporting Service lets attackers gain SYSTEM access, and it's actively exploited in the wild. |
| 2024-04-23 | CVE-2022-38028 | high | Microsoft Windows Print Spooler vulnerability (CVE-2022-38028) allows attackers to execute arbitrary code with SYSTEM privileges by modifying a JavaScript constraints file. |
| 2024-03-04 | CVE-2024-21338 | critical | A local privilege escalation flaw in Windows appid.sys was actively exploited in the wild to enable ransomware attacks. |
| 2024-02-13 | CVE-2024-21412 | critical | An unpatched Windows Internet Shortcut bypass vulnerability was actively exploited in the wild to deliver ransomware. |
| 2023-04-11 | CVE-2023-28252 | critical | An unpatched privilege escalation flaw in the Windows CLFS driver was actively exploited in the wild to enable ransomware attacks. |
| 2023-04-07 | CVE-2019-1388 | critical | An unpatched Windows privilege escalation flaw allowed attackers to run elevated processes, directly enabling ransomware campaigns. |
| 2023-03-14 | CVE-2023-24880 | critical | An attacker can bypass Windows SmartScreen's Mark of the Web defenses using a specially crafted malicious file. |
| 2023-02-14 | CVE-2023-23376 | critical | An unpatched privilege escalation flaw in the Windows CLFS driver was actively exploited in the wild to enable ransomware attacks. |
| 2022-11-08 | CVE-2022-41073 | critical | An unpatched Windows Print Spooler flaw allowed attackers to escalate privileges to SYSTEM, directly enabling ransomware deployments. |
| 2022-11-08 | CVE-2022-41091 | critical | An unpatched bypass in Windows' Mark of the Web feature allowed ransomware actors to evade security controls and execute malicious code. |
| 2022-06-14 | CVE-2022-30190 | critical | An unpatched RCE flaw in Microsoft's Windows Support Diagnostic Tool allowed attackers to execute arbitrary code via URL protocol calls from applications like Word. |
| 2022-05-25 | CVE-2015-1671 | high | A remote code execution flaw in Windows TrueType font handling was actively exploited in the wild, allowing attackers to execute arbitrary code on unpatched systems. |
| 2022-05-25 | CVE-2014-4148 | high | A remote code execution vulnerability in Windows kernel-mode drivers handling TrueType fonts was actively exploited in the wild. |
| 2021-11-03 | CVE-2021-36942 | critical | A Microsoft Windows vulnerability allowed attackers to spoof the Local Security Authority and force domain controllers to authenticate against malicious servers using NTLM. |
| 2025-03-11 | CVE-2025-26633 | critical | An unpatched MMC vulnerability in Windows allows local attackers to bypass security features, and it is actively exploited in the wild. |
| 2023-07-17 | CVE-2023-36884 | critical | A Microsoft Windows Search vulnerability allowed attackers to bypass MOTW protections and execute remote code via malicious files. |
| 2022-05-25 | CVE-2016-3393 | high | A remote code execution flaw in Windows GDI allowed attackers to take control of systems, remaining unpatched long enough to be added to CISA's KEV catalog. |
| 2022-05-25 | CVE-2016-7256 | high | A remote code execution flaw in Windows font handling was actively exploited in the wild, allowing attackers to take control of systems. |
| 2022-05-24 | CVE-2018-8611 | high | A Windows kernel privilege escalation vulnerability (CVE-2018-8611) was actively exploited in the wild, allowing attackers to escalate privileges without remote code execution. |
| 2022-05-24 | CVE-2017-8543 | high | An unpatched Windows Search vulnerability allowed remote attackers to execute arbitrary code and take full control of affected systems. |
| 2022-05-23 | CVE-2020-1027 | high | A Windows kernel privilege escalation flaw allowed attackers to gain elevated permissions and execute arbitrary code. |
| 2022-05-23 | CVE-2019-0880 | high | A local privilege escalation flaw in Windows splwow64.exe allowed attackers to elevate from low to medium integrity, enabling further system compromise. |
| 2022-05-25 | CVE-2015-1769 | high | Microsoft Windows Mount Manager improperly processes symbolic links, allowing privilege escalation. |
| 2022-05-25 | CVE-2015-6175 | high | A local privilege escalation vulnerability in the Windows kernel allowed attackers to gain elevated access via a crafted application. |
| 2026-02-17 | CVE-2008-0015 | high | CVE-2008-0015: RCE in Windows Video ActiveX Control exploited in the wild |
| 2026-02-10 | CVE-2026-21525 | high | Microsoft Windows exposed to remote denial of service via NULL pointer dereference |
| 2026-02-10 | CVE-2026-21510 | high | Microsoft Windows Shell Protection Mechanism Vulnerability actively exploited |
| 2026-02-10 | CVE-2026-21519 | high | Authorized attackers could elevate privileges on Windows systems due to a local type confusion vulnerability. |
| 2026-02-10 | CVE-2026-21533 | high | Authorized attackers could elevate privileges locally in Microsoft Windows due to an improper privilege management vulnerability. |
| 2026-02-10 | CVE-2026-21513 | high | Microsoft's MSHTML Framework allowed unauthorized attackers to bypass security features over a network. |
| 2026-01-13 | CVE-2026-20805 | high | Authorized attackers can disclose information on Windows systems due to an unpatched vulnerability. |
| 2025-12-09 | CVE-2025-62221 | high | Authorized attackers can elevate privileges on Windows systems due to a use after free vulnerability in the Cloud Files Mini Filter Driver. |
| 2025-11-12 | CVE-2025-62215 | high | Race condition in Windows kernel allows local escalation to SYSTEM-level access |
| 2025-10-24 | CVE-2025-59287 | high | WSUS RCE |
| 2025-10-20 | CVE-2025-33073 | high | Microsoft Windows SMB Client improper access control allowed remote code execution |
| 2025-10-14 | CVE-2025-24990 | high | Untrusted pointer dereference in Microsoft Windows allowed privilege escalation to admin |
| 2025-10-14 | CVE-2025-59230 | high | Authorized attackers could elevate privileges on Windows systems due to an improper access control vulnerability in the Remote Access Connection Manager. |
| 2025-10-06 | CVE-2011-3402 | high | CVE-2011-3402: Remote code execution in Windows due to unpatched TrueType font parsing engine flaw |
| 2025-10-06 | CVE-2021-43226 | high | Microsoft Windows exploited for privilege escalation locally without patch |
| 2025-10-06 | CVE-2013-3918 | high | Microsoft Windows Out-of-Bounds Write Vulnerability allowed remote code execution. |
| 2025-06-10 | CVE-2025-33053 | high | Microsoft Windows exposed to remote code execution via malicious WebDAV shortcuts |
| 2025-05-13 | CVE-2025-30400 | high | A use-after-free vulnerability in the Windows DWM Core Library allows local privilege escalation and is currently being exploited in the wild. |
| 2025-05-13 | CVE-2025-32701 | high | A use-after-free vulnerability in the Microsoft CLFS driver allows local privilege escalation and is currently being exploited in the wild. |
| 2025-03-11 | CVE-2025-24993 | high | A Microsoft Windows NTFS heap buffer overflow vulnerability is actively being exploited, allowing local code execution by an attacker. |
| 2023-11-14 | CVE-2023-36033 | high | Microsoft Windows DWM Core Library privilege escalation vulnerability |
| 2023-11-14 | CVE-2023-36025 | high | Microsoft Windows SmartScreen Security Feature Bypass Vulnerability |
| 2023-11-14 | CVE-2023-36036 | high | Microsoft Windows Cloud Files Mini Filter Driver privilege escalation vulnerability allows SYSTEM privilege gain. |
| 2023-07-11 | CVE-2023-32046 | high | A Microsoft Windows MSHTML vulnerability allows privilege escalation and is currently being exploited in the wild, impacting DIB organizations using Windows systems. |
| 2023-07-11 | CVE-2023-36874 | high | A Microsoft Windows Error Reporting Service vulnerability allows privilege escalation, and is currently being exploited in the wild. |
DOSSIER SOURCES
- MICROSOFT CORP (MSFT, US5949181045) - Company Profile · financialdata.net
- Microsoft (MSFT) Company Profile & Description - Stock Analysis · stockanalysis.com
- CISA Confirms BlueHammer CVE-2026-33825 Used in Ransomware · dailysecurityreview.com
- Microsoft Windows Security Vulnerabilities in 2026 · stack.watch
- June 2026 CVEs: 57 Actively Exploited, Patch Exposed Assets First · windowsforum.com
Open questions: Why are critical vulnerabilities in Windows still actively exploited in 2026? · What is the root cause of repeated driver vulnerabilities in Windows?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 17:48:42.850246+00:00