FAIL › dossier
windows
PRODUCT· dossier confidence 40%
Microsoft Windows is a critical software asset with a high volume of actively exploited vulnerabilities in 2026, including ransomware campaigns targeting Windows Defender and multiple critical RCE flaws in the OS and ecosystem.
PROFILE
CategorySoftware VendorWhat they doMicrosoft Corporation develops and supports software, services, devices, and solutions worldwide, including the Windows operating system and Microsoft 365 commercial products.Ownershippublic
Websitehttps://www.microsoft.com ↗
SECURITY POSTURE
Microsoft Windows demonstrates a high volume of actively exploited vulnerabilities, including multiple critical RCE and privilege escalation flaws in 2026, with active exploitation confirmed by CISA and industry forums.
Notable failures
- CVE-2025-60710: Privilege escalation via link-following flaw
- CVE-2026-32202: Network spoofing bypassing authentication
- CVE-2026-13776: Critical sandbox escape in Chrome renderer process
- CVE-2026-33825: BlueHammer ransomware exploitation of Windows Defender
- CVE-2026-45607: Hyper-V Remote Code Execution
- CVE-2026-40404: UDFS Elevation of Privilege
Patterns: Repeated unpatched edge-device RCEs; Active exploitation of privilege escalation flaws; High volume of critical vulnerabilities in 2026
FAILURE HISTORY · 60
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-03-25 | CVE-2017-0146 | critical | A critical Windows vulnerability allowed remote code execution via SMBv1, actively exploited and linked to ransomware attacks, demonstrating a failure to patch a known risk. |
| 2022-02-15 | CVE-2018-8174 | critical | A critical, actively exploited Windows VBScript engine vulnerability allows remote code execution. |
| 2021-11-03 | CVE-2021-1675 | critical | A critical, actively exploited Windows Print Spooler vulnerability allows for remote code execution. |
| 2021-11-03 | CVE-2017-0143 | critical | A critical, actively exploited vulnerability in Microsoft's SMBv1 allowed for remote code execution, impacting many DIB systems still running vulnerable Windows versions. |
| 2023-01-10 | CVE-2023-21674 | high | Microsoft Windows ALPC flaw exploited in wild for privilege escalation |
| 2022-09-14 | CVE-2022-37969 | high | Microsoft Windows CLFS Driver allows unauthorized escalation of privileges |
| 2026-04-13 | CVE-2025-60710 | high | Microsoft Windows is actively exploited for privilege escalation via CVE-2025-60710, a link-following flaw enabling unauthorized admin access. |
| 2025-04-08 | CVE-2025-29824 | critical | A use-after-free vulnerability in the Windows CLFS driver allows local privilege escalation and is actively exploited by ransomware. |
| 2025-03-03 | CVE-2018-8639 | critical | A local, authenticated privilege escalation flaw in Windows Win32k allowed attackers to run arbitrary kernel-mode code, leading to ransomware outbreaks. |
| 2024-11-12 | CVE-2024-49039 | critical | An unpatched privilege escalation flaw in Windows Task Scheduler lets attackers bypass AppContainer restrictions and execute privileged RPC calls. |
| 2024-10-15 | CVE-2024-30088 | critical | A TOCTOU race condition in the Windows kernel allows privilege escalation and is actively exploited in the wild. |
| 2024-06-13 | CVE-2024-26169 | critical | A local privilege escalation flaw in Windows Error Reporting Service lets attackers gain SYSTEM access, and it's actively exploited in the wild. |
| 2024-04-23 | CVE-2022-38028 | high | Microsoft Windows Print Spooler vulnerability (CVE-2022-38028) allows attackers to execute arbitrary code with SYSTEM privileges by modifying a JavaScript constraints file. |
| 2024-03-04 | CVE-2024-21338 | critical | A local privilege escalation flaw in Windows appid.sys was actively exploited in the wild to enable ransomware attacks. |
| 2024-02-13 | CVE-2024-21412 | critical | An unpatched Windows Internet Shortcut bypass vulnerability was actively exploited in the wild to deliver ransomware. |
| 2023-04-11 | CVE-2023-28252 | critical | An unpatched privilege escalation flaw in the Windows CLFS driver was actively exploited in the wild to enable ransomware attacks. |
| 2023-04-07 | CVE-2019-1388 | critical | An unpatched Windows privilege escalation flaw allowed attackers to run elevated processes, directly enabling ransomware campaigns. |
| 2023-03-14 | CVE-2023-24880 | critical | An attacker can bypass Windows SmartScreen's Mark of the Web defenses using a specially crafted malicious file. |
| 2023-02-14 | CVE-2023-23376 | critical | An unpatched privilege escalation flaw in the Windows CLFS driver was actively exploited in the wild to enable ransomware attacks. |
| 2022-11-08 | CVE-2022-41091 | critical | An unpatched bypass in Windows' Mark of the Web feature allowed ransomware actors to evade security controls and execute malicious code. |
| 2022-11-08 | CVE-2022-41073 | critical | An unpatched Windows Print Spooler flaw allowed attackers to escalate privileges to SYSTEM, directly enabling ransomware deployments. |
| 2022-06-14 | CVE-2022-30190 | critical | An unpatched RCE flaw in Microsoft's Windows Support Diagnostic Tool allowed attackers to execute arbitrary code via URL protocol calls from applications like Word. |
| 2022-05-25 | CVE-2015-1671 | high | A remote code execution flaw in Windows TrueType font handling was actively exploited in the wild, allowing attackers to execute arbitrary code on unpatched systems. |
| 2022-05-25 | CVE-2014-4148 | high | A remote code execution vulnerability in Windows kernel-mode drivers handling TrueType fonts was actively exploited in the wild. |
| 2022-03-25 | CVE-2014-6332 | high | A 2014 OLE automation array RCE in Windows was actively exploited in the wild and remains in CISA's KEV catalog. |
| 2022-03-03 | CVE-2009-1123 | high | A 2009 Windows kernel privilege escalation flaw was actively exploited in the wild for years before patching. |
| 2022-02-25 | CVE-2014-6352 | high | A remote code execution flaw in Windows OLE objects was actively exploited in the wild, enabling attackers to execute arbitrary code without user interaction. |
| 2021-11-03 | CVE-2020-1350 | high | Microsoft Windows DNS Servers suffered a remote code execution flaw (CVE-2020-1350, SIGRed) that allowed attackers to execute arbitrary code as the Local System Account. |
| 2021-11-03 | CVE-2020-0986 | high | An unpatched Windows kernel privilege escalation flaw allowed attackers to execute arbitrary code in kernel mode. |
| 2021-11-03 | CVE-2021-36942 | critical | A Microsoft Windows vulnerability allowed attackers to spoof the Local Security Authority and force domain controllers to authenticate against malicious servers using NTLM. |
| 2025-03-11 | CVE-2025-26633 | critical | An unpatched MMC vulnerability in Windows allows local attackers to bypass security features, and it is actively exploited in the wild. |
| 2023-07-17 | CVE-2023-36884 | critical | A Microsoft Windows Search vulnerability allowed attackers to bypass MOTW protections and execute remote code via malicious files. |
| 2022-05-25 | CVE-2016-3393 | high | A remote code execution flaw in Windows GDI allowed attackers to take control of systems, remaining unpatched long enough to be added to CISA's KEV catalog. |
| 2022-05-25 | CVE-2016-7256 | high | A remote code execution flaw in Windows font handling was actively exploited in the wild, allowing attackers to take control of systems. |
| 2022-05-24 | CVE-2018-8611 | high | A Windows kernel privilege escalation vulnerability (CVE-2018-8611) was actively exploited in the wild, allowing attackers to escalate privileges without remote code execution. |
| 2022-05-24 | CVE-2017-8543 | high | An unpatched Windows Search vulnerability allowed remote attackers to execute arbitrary code and take full control of affected systems. |
| 2022-05-23 | CVE-2020-1027 | high | A Windows kernel privilege escalation flaw allowed attackers to gain elevated permissions and execute arbitrary code. |
| 2022-05-23 | CVE-2019-0880 | high | A local privilege escalation flaw in Windows splwow64.exe allowed attackers to elevate from low to medium integrity, enabling further system compromise. |
| 2022-04-25 | CVE-2022-26904 | high | A privilege escalation vulnerability in Windows User Profile Service was actively exploited in the wild, allowing attackers to escalate privileges without requiring remote code execution. |
| 2022-04-25 | CVE-2022-21919 | high | A privilege escalation vulnerability in the Windows User Profile Service was actively exploited in the wild, allowing attackers to escalate privileges on unpatched systems. |
| 2022-03-31 | CVE-2021-34484 | high | A privilege escalation vulnerability in the Windows User Profile Service was actively exploited in the wild, allowing attackers to escalate privileges without requiring remote code execution. |
| 2022-03-28 | CVE-2015-2426 | high | A remote code execution flaw in Windows' Adobe Type Manager Library allowed attackers to execute arbitrary code via specially crafted OpenType fonts. |
| 2022-03-03 | CVE-2002-0367 | high | A 2002 Windows privilege escalation flaw in smss.exe allowed local users to gain SYSTEM privileges without proper authentication. |
| 2022-03-03 | CVE-2004-0210 | high | A 20-year-old Windows privilege escalation flaw in the POSIX subsystem allows local users to gain full system control. |
| 2022-03-03 | CVE-2014-4114 | high | A 2014 Windows OLE remote code execution flaw was actively exploited in the wild, proving that years-old unpatched vulnerabilities remain a critical threat. |
| 2022-03-03 | CVE-2010-0232 | high | A 2010 Windows kernel flaw allowed local privilege escalation via unvalidated BIOS calls when 16-bit app support was enabled. |
| 2022-02-10 | CVE-2021-36934 | high | A Windows SAM local privilege escalation vulnerability allowed any user to read the SAM file and escalate to SYSTEM level if a Volume Shadow Copy was available. |
| 2022-02-10 | CVE-2017-8464 | high | A crafted .LNK file triggered remote code execution in Windows Shell, a flaw actively exploited in the wild and now on CISA's KEV list. |
| 2021-11-03 | CVE-2019-1214 | high | A privilege escalation vulnerability in the Windows CLFS driver was actively exploited in the wild, allowing attackers to escalate privileges without remote code execution. |
| 2021-11-03 | CVE-2019-0863 | high | A privilege escalation vulnerability in Windows Error Reporting allowed kernel-mode code execution, listed in CISA's KEV catalog as actively exploited. |
| 2021-11-03 | CVE-2016-0185 | high | A remote code execution flaw in Windows Media Center allowed attackers to execute arbitrary code via malicious .mcl files. |
| 2021-11-03 | CVE-2020-0601 | high | Microsoft Windows CryptoAPI spoofing vulnerability allowed attackers to use fake code-signing certificates to sign malicious executables and decrypt user connections. |
| 2021-11-03 | CVE-2020-1020 | high | A remote code execution flaw in Windows' Adobe Font Manager Library allowed attackers to execute arbitrary code on systems running Windows 10 and earlier. |
| 2021-11-03 | CVE-2021-33771 | high | An unpatched Windows kernel privilege escalation vulnerability was actively exploited in the wild, allowing attackers to escalate privileges without remote code execution. |
| 2022-05-25 | CVE-2015-1769 | high | Microsoft Windows Mount Manager improperly processes symbolic links, allowing privilege escalation. |
| 2022-05-25 | CVE-2015-6175 | high | A local privilege escalation vulnerability in the Windows kernel allowed attackers to gain elevated access via a crafted application. |
| 2022-04-19 | CVE-2022-22718 | high | An unpatched Windows Print Spooler privilege escalation vulnerability (CVE-2022-22718) was actively exploited in the wild, allowing attackers to escalate privileges on Windows systems. |
| 2022-03-28 | CVE-2021-34486 | high | A privilege escalation vulnerability in Windows Event Tracing was actively exploited in the wild, allowing attackers to escalate privileges without requiring remote code execution. |
| 2022-03-25 | CVE-2018-8414 | high | Microsoft Windows Shell remote code execution vulnerability allows attackers to execute arbitrary code via improper file path validation. |
| 2021-11-03 | CVE-2021-36948 | high | An unpatched privilege escalation flaw in Windows Update Medic Service was actively exploited in the wild, allowing attackers to escalate privileges on Windows systems. |
DOSSIER SOURCES
- MICROSOFT CORP (MSFT, US5949181045) - Company Profile · financialdata.net
- Microsoft (MSFT) Company Profile & Description - Stock Analysis · stockanalysis.com
- CISA Confirms BlueHammer CVE-2026-33825 Used in Ransomware · dailysecurityreview.com
- Microsoft Windows Security Vulnerabilities in 2026 · stack.watch
- June 2026 CVEs: 57 Actively Exploited, Patch Exposed Assets First · windowsforum.com
Open questions: Why are critical vulnerabilities in Windows still actively exploited in 2026? · What is the root cause of repeated driver vulnerabilities in Windows?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 17:48:42.850246+00:00