Skip to content
COOEY

FAIL › dossier

windows

PRODUCT

· dossier confidence 40%

Microsoft Windows is a critical software asset with a high volume of actively exploited vulnerabilities in 2026, including ransomware campaigns targeting Windows Defender and multiple critical RCE flaws in the OS and ecosystem.

PROFILE
CategorySoftware VendorWhat they doMicrosoft Corporation develops and supports software, services, devices, and solutions worldwide, including the Windows operating system and Microsoft 365 commercial products.Ownershippublic Websitehttps://www.microsoft.com ↗
SECURITY POSTURE

Microsoft Windows demonstrates a high volume of actively exploited vulnerabilities, including multiple critical RCE and privilege escalation flaws in 2026, with active exploitation confirmed by CISA and industry forums.

Notable failures
  • CVE-2025-60710: Privilege escalation via link-following flaw
  • CVE-2026-32202: Network spoofing bypassing authentication
  • CVE-2026-13776: Critical sandbox escape in Chrome renderer process
  • CVE-2026-33825: BlueHammer ransomware exploitation of Windows Defender
  • CVE-2026-45607: Hyper-V Remote Code Execution
  • CVE-2026-40404: UDFS Elevation of Privilege
Patterns: Repeated unpatched edge-device RCEs; Active exploitation of privilege escalation flaws; High volume of critical vulnerabilities in 2026
FAILURE HISTORY · 60
DATEEVENTSEVSUMMARY
2022-03-25 CVE-2017-0146 critical A critical Windows vulnerability allowed remote code execution via SMBv1, actively exploited and linked to ransomware attacks, demonstrating a failure to patch a known risk.
2022-02-15 CVE-2018-8174 critical A critical, actively exploited Windows VBScript engine vulnerability allows remote code execution.
2021-11-03 CVE-2017-0143 critical A critical, actively exploited vulnerability in Microsoft's SMBv1 allowed for remote code execution, impacting many DIB systems still running vulnerable Windows versions.
2021-11-03 CVE-2021-1675 critical A critical, actively exploited Windows Print Spooler vulnerability allows for remote code execution.
2023-01-10 CVE-2023-21674 high Microsoft Windows ALPC flaw exploited in wild for privilege escalation
2022-09-14 CVE-2022-37969 high Microsoft Windows CLFS Driver allows unauthorized escalation of privileges
2026-04-13 CVE-2025-60710 high Microsoft Windows is actively exploited for privilege escalation via CVE-2025-60710, a link-following flaw enabling unauthorized admin access.
2025-04-08 CVE-2025-29824 critical A use-after-free vulnerability in the Windows CLFS driver allows local privilege escalation and is actively exploited by ransomware.
2025-03-03 CVE-2018-8639 critical A local, authenticated privilege escalation flaw in Windows Win32k allowed attackers to run arbitrary kernel-mode code, leading to ransomware outbreaks.
2024-11-12 CVE-2024-49039 critical An unpatched privilege escalation flaw in Windows Task Scheduler lets attackers bypass AppContainer restrictions and execute privileged RPC calls.
2024-10-15 CVE-2024-30088 critical A TOCTOU race condition in the Windows kernel allows privilege escalation and is actively exploited in the wild.
2024-06-13 CVE-2024-26169 critical A local privilege escalation flaw in Windows Error Reporting Service lets attackers gain SYSTEM access, and it's actively exploited in the wild.
2024-04-23 CVE-2022-38028 high Microsoft Windows Print Spooler vulnerability (CVE-2022-38028) allows attackers to execute arbitrary code with SYSTEM privileges by modifying a JavaScript constraints file.
2024-03-04 CVE-2024-21338 critical A local privilege escalation flaw in Windows appid.sys was actively exploited in the wild to enable ransomware attacks.
2024-02-13 CVE-2024-21412 critical An unpatched Windows Internet Shortcut bypass vulnerability was actively exploited in the wild to deliver ransomware.
2023-04-11 CVE-2023-28252 critical An unpatched privilege escalation flaw in the Windows CLFS driver was actively exploited in the wild to enable ransomware attacks.
2023-04-07 CVE-2019-1388 critical An unpatched Windows privilege escalation flaw allowed attackers to run elevated processes, directly enabling ransomware campaigns.
2023-03-14 CVE-2023-24880 critical An attacker can bypass Windows SmartScreen's Mark of the Web defenses using a specially crafted malicious file.
2023-02-14 CVE-2023-23376 critical An unpatched privilege escalation flaw in the Windows CLFS driver was actively exploited in the wild to enable ransomware attacks.
2022-11-08 CVE-2022-41073 critical An unpatched Windows Print Spooler flaw allowed attackers to escalate privileges to SYSTEM, directly enabling ransomware deployments.
2022-11-08 CVE-2022-41091 critical An unpatched bypass in Windows' Mark of the Web feature allowed ransomware actors to evade security controls and execute malicious code.
2022-06-14 CVE-2022-30190 critical An unpatched RCE flaw in Microsoft's Windows Support Diagnostic Tool allowed attackers to execute arbitrary code via URL protocol calls from applications like Word.
2022-05-25 CVE-2015-1671 high A remote code execution flaw in Windows TrueType font handling was actively exploited in the wild, allowing attackers to execute arbitrary code on unpatched systems.
2022-05-25 CVE-2014-4148 high A remote code execution vulnerability in Windows kernel-mode drivers handling TrueType fonts was actively exploited in the wild.
2021-11-03 CVE-2021-36942 critical A Microsoft Windows vulnerability allowed attackers to spoof the Local Security Authority and force domain controllers to authenticate against malicious servers using NTLM.
2025-03-11 CVE-2025-26633 critical An unpatched MMC vulnerability in Windows allows local attackers to bypass security features, and it is actively exploited in the wild.
2023-07-17 CVE-2023-36884 critical A Microsoft Windows Search vulnerability allowed attackers to bypass MOTW protections and execute remote code via malicious files.
2022-05-25 CVE-2016-3393 high A remote code execution flaw in Windows GDI allowed attackers to take control of systems, remaining unpatched long enough to be added to CISA's KEV catalog.
2022-05-25 CVE-2016-7256 high A remote code execution flaw in Windows font handling was actively exploited in the wild, allowing attackers to take control of systems.
2022-05-24 CVE-2018-8611 high A Windows kernel privilege escalation vulnerability (CVE-2018-8611) was actively exploited in the wild, allowing attackers to escalate privileges without remote code execution.
2022-05-24 CVE-2017-8543 high An unpatched Windows Search vulnerability allowed remote attackers to execute arbitrary code and take full control of affected systems.
2022-05-23 CVE-2020-1027 high A Windows kernel privilege escalation flaw allowed attackers to gain elevated permissions and execute arbitrary code.
2022-05-23 CVE-2019-0880 high A local privilege escalation flaw in Windows splwow64.exe allowed attackers to elevate from low to medium integrity, enabling further system compromise.
2022-05-25 CVE-2015-1769 high Microsoft Windows Mount Manager improperly processes symbolic links, allowing privilege escalation.
2022-05-25 CVE-2015-6175 high A local privilege escalation vulnerability in the Windows kernel allowed attackers to gain elevated access via a crafted application.
2026-02-17 CVE-2008-0015 high CVE-2008-0015: RCE in Windows Video ActiveX Control exploited in the wild
2026-02-10 CVE-2026-21525 high Microsoft Windows exposed to remote denial of service via NULL pointer dereference
2026-02-10 CVE-2026-21510 high Microsoft Windows Shell Protection Mechanism Vulnerability actively exploited
2026-02-10 CVE-2026-21519 high Authorized attackers could elevate privileges on Windows systems due to a local type confusion vulnerability.
2026-02-10 CVE-2026-21533 high Authorized attackers could elevate privileges locally in Microsoft Windows due to an improper privilege management vulnerability.
2026-02-10 CVE-2026-21513 high Microsoft's MSHTML Framework allowed unauthorized attackers to bypass security features over a network.
2026-01-13 CVE-2026-20805 high Authorized attackers can disclose information on Windows systems due to an unpatched vulnerability.
2025-12-09 CVE-2025-62221 high Authorized attackers can elevate privileges on Windows systems due to a use after free vulnerability in the Cloud Files Mini Filter Driver.
2025-11-12 CVE-2025-62215 high Race condition in Windows kernel allows local escalation to SYSTEM-level access
2025-10-24 CVE-2025-59287 high WSUS RCE
2025-10-20 CVE-2025-33073 high Microsoft Windows SMB Client improper access control allowed remote code execution
2025-10-14 CVE-2025-24990 high Untrusted pointer dereference in Microsoft Windows allowed privilege escalation to admin
2025-10-14 CVE-2025-59230 high Authorized attackers could elevate privileges on Windows systems due to an improper access control vulnerability in the Remote Access Connection Manager.
2025-10-06 CVE-2011-3402 high CVE-2011-3402: Remote code execution in Windows due to unpatched TrueType font parsing engine flaw
2025-10-06 CVE-2021-43226 high Microsoft Windows exploited for privilege escalation locally without patch
2025-10-06 CVE-2013-3918 high Microsoft Windows Out-of-Bounds Write Vulnerability allowed remote code execution.
2025-06-10 CVE-2025-33053 high Microsoft Windows exposed to remote code execution via malicious WebDAV shortcuts
2025-05-13 CVE-2025-30400 high A use-after-free vulnerability in the Windows DWM Core Library allows local privilege escalation and is currently being exploited in the wild.
2025-05-13 CVE-2025-32701 high A use-after-free vulnerability in the Microsoft CLFS driver allows local privilege escalation and is currently being exploited in the wild.
2025-03-11 CVE-2025-24993 high A Microsoft Windows NTFS heap buffer overflow vulnerability is actively being exploited, allowing local code execution by an attacker.
2023-11-14 CVE-2023-36033 high Microsoft Windows DWM Core Library privilege escalation vulnerability
2023-11-14 CVE-2023-36025 high Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
2023-11-14 CVE-2023-36036 high Microsoft Windows Cloud Files Mini Filter Driver privilege escalation vulnerability allows SYSTEM privilege gain.
2023-07-11 CVE-2023-32046 high A Microsoft Windows MSHTML vulnerability allows privilege escalation and is currently being exploited in the wild, impacting DIB organizations using Windows systems.
2023-07-11 CVE-2023-36874 high A Microsoft Windows Error Reporting Service vulnerability allows privilege escalation, and is currently being exploited in the wild.
Open questions: Why are critical vulnerabilities in Windows still actively exploited in 2026? · What is the root cause of repeated driver vulnerabilities in Windows?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 17:48:42.850246+00:00