Skip to content
COOEY

FAIL › dossier

windows

PRODUCT

· dossier confidence 40%

Microsoft Windows is a critical software asset with a high volume of actively exploited vulnerabilities in 2026, including ransomware campaigns targeting Windows Defender and multiple critical RCE flaws in the OS and ecosystem.

PROFILE
CategorySoftware VendorWhat they doMicrosoft Corporation develops and supports software, services, devices, and solutions worldwide, including the Windows operating system and Microsoft 365 commercial products.Ownershippublic Websitehttps://www.microsoft.com ↗
SECURITY POSTURE

Microsoft Windows demonstrates a high volume of actively exploited vulnerabilities, including multiple critical RCE and privilege escalation flaws in 2026, with active exploitation confirmed by CISA and industry forums.

Notable failures
  • CVE-2025-60710: Privilege escalation via link-following flaw
  • CVE-2026-32202: Network spoofing bypassing authentication
  • CVE-2026-13776: Critical sandbox escape in Chrome renderer process
  • CVE-2026-33825: BlueHammer ransomware exploitation of Windows Defender
  • CVE-2026-45607: Hyper-V Remote Code Execution
  • CVE-2026-40404: UDFS Elevation of Privilege
Patterns: Repeated unpatched edge-device RCEs; Active exploitation of privilege escalation flaws; High volume of critical vulnerabilities in 2026
FAILURE HISTORY · 60
DATEEVENTSEVSUMMARY
2022-03-25 CVE-2017-0146 critical A critical Windows vulnerability allowed remote code execution via SMBv1, actively exploited and linked to ransomware attacks, demonstrating a failure to patch a known risk.
2022-02-15 CVE-2018-8174 critical A critical, actively exploited Windows VBScript engine vulnerability allows remote code execution.
2021-11-03 CVE-2021-1675 critical A critical, actively exploited Windows Print Spooler vulnerability allows for remote code execution.
2021-11-03 CVE-2017-0143 critical A critical, actively exploited vulnerability in Microsoft's SMBv1 allowed for remote code execution, impacting many DIB systems still running vulnerable Windows versions.
2023-01-10 CVE-2023-21674 high Microsoft Windows ALPC flaw exploited in wild for privilege escalation
2022-09-14 CVE-2022-37969 high Microsoft Windows CLFS Driver allows unauthorized escalation of privileges
2026-04-13 CVE-2025-60710 high Microsoft Windows is actively exploited for privilege escalation via CVE-2025-60710, a link-following flaw enabling unauthorized admin access.
2025-04-08 CVE-2025-29824 critical A use-after-free vulnerability in the Windows CLFS driver allows local privilege escalation and is actively exploited by ransomware.
2025-03-03 CVE-2018-8639 critical A local, authenticated privilege escalation flaw in Windows Win32k allowed attackers to run arbitrary kernel-mode code, leading to ransomware outbreaks.
2024-11-12 CVE-2024-49039 critical An unpatched privilege escalation flaw in Windows Task Scheduler lets attackers bypass AppContainer restrictions and execute privileged RPC calls.
2024-10-15 CVE-2024-30088 critical A TOCTOU race condition in the Windows kernel allows privilege escalation and is actively exploited in the wild.
2024-06-13 CVE-2024-26169 critical A local privilege escalation flaw in Windows Error Reporting Service lets attackers gain SYSTEM access, and it's actively exploited in the wild.
2024-04-23 CVE-2022-38028 high Microsoft Windows Print Spooler vulnerability (CVE-2022-38028) allows attackers to execute arbitrary code with SYSTEM privileges by modifying a JavaScript constraints file.
2024-03-04 CVE-2024-21338 critical A local privilege escalation flaw in Windows appid.sys was actively exploited in the wild to enable ransomware attacks.
2024-02-13 CVE-2024-21412 critical An unpatched Windows Internet Shortcut bypass vulnerability was actively exploited in the wild to deliver ransomware.
2023-04-11 CVE-2023-28252 critical An unpatched privilege escalation flaw in the Windows CLFS driver was actively exploited in the wild to enable ransomware attacks.
2023-04-07 CVE-2019-1388 critical An unpatched Windows privilege escalation flaw allowed attackers to run elevated processes, directly enabling ransomware campaigns.
2023-03-14 CVE-2023-24880 critical An attacker can bypass Windows SmartScreen's Mark of the Web defenses using a specially crafted malicious file.
2023-02-14 CVE-2023-23376 critical An unpatched privilege escalation flaw in the Windows CLFS driver was actively exploited in the wild to enable ransomware attacks.
2022-11-08 CVE-2022-41091 critical An unpatched bypass in Windows' Mark of the Web feature allowed ransomware actors to evade security controls and execute malicious code.
2022-11-08 CVE-2022-41073 critical An unpatched Windows Print Spooler flaw allowed attackers to escalate privileges to SYSTEM, directly enabling ransomware deployments.
2022-06-14 CVE-2022-30190 critical An unpatched RCE flaw in Microsoft's Windows Support Diagnostic Tool allowed attackers to execute arbitrary code via URL protocol calls from applications like Word.
2022-05-25 CVE-2015-1671 high A remote code execution flaw in Windows TrueType font handling was actively exploited in the wild, allowing attackers to execute arbitrary code on unpatched systems.
2022-05-25 CVE-2014-4148 high A remote code execution vulnerability in Windows kernel-mode drivers handling TrueType fonts was actively exploited in the wild.
2022-03-25 CVE-2014-6332 high A 2014 OLE automation array RCE in Windows was actively exploited in the wild and remains in CISA's KEV catalog.
2022-03-03 CVE-2009-1123 high A 2009 Windows kernel privilege escalation flaw was actively exploited in the wild for years before patching.
2022-02-25 CVE-2014-6352 high A remote code execution flaw in Windows OLE objects was actively exploited in the wild, enabling attackers to execute arbitrary code without user interaction.
2021-11-03 CVE-2020-1350 high Microsoft Windows DNS Servers suffered a remote code execution flaw (CVE-2020-1350, SIGRed) that allowed attackers to execute arbitrary code as the Local System Account.
2021-11-03 CVE-2020-0986 high An unpatched Windows kernel privilege escalation flaw allowed attackers to execute arbitrary code in kernel mode.
2021-11-03 CVE-2021-36942 critical A Microsoft Windows vulnerability allowed attackers to spoof the Local Security Authority and force domain controllers to authenticate against malicious servers using NTLM.
2025-03-11 CVE-2025-26633 critical An unpatched MMC vulnerability in Windows allows local attackers to bypass security features, and it is actively exploited in the wild.
2023-07-17 CVE-2023-36884 critical A Microsoft Windows Search vulnerability allowed attackers to bypass MOTW protections and execute remote code via malicious files.
2022-05-25 CVE-2016-3393 high A remote code execution flaw in Windows GDI allowed attackers to take control of systems, remaining unpatched long enough to be added to CISA's KEV catalog.
2022-05-25 CVE-2016-7256 high A remote code execution flaw in Windows font handling was actively exploited in the wild, allowing attackers to take control of systems.
2022-05-24 CVE-2018-8611 high A Windows kernel privilege escalation vulnerability (CVE-2018-8611) was actively exploited in the wild, allowing attackers to escalate privileges without remote code execution.
2022-05-24 CVE-2017-8543 high An unpatched Windows Search vulnerability allowed remote attackers to execute arbitrary code and take full control of affected systems.
2022-05-23 CVE-2020-1027 high A Windows kernel privilege escalation flaw allowed attackers to gain elevated permissions and execute arbitrary code.
2022-05-23 CVE-2019-0880 high A local privilege escalation flaw in Windows splwow64.exe allowed attackers to elevate from low to medium integrity, enabling further system compromise.
2022-04-25 CVE-2022-26904 high A privilege escalation vulnerability in Windows User Profile Service was actively exploited in the wild, allowing attackers to escalate privileges without requiring remote code execution.
2022-04-25 CVE-2022-21919 high A privilege escalation vulnerability in the Windows User Profile Service was actively exploited in the wild, allowing attackers to escalate privileges on unpatched systems.
2022-03-31 CVE-2021-34484 high A privilege escalation vulnerability in the Windows User Profile Service was actively exploited in the wild, allowing attackers to escalate privileges without requiring remote code execution.
2022-03-28 CVE-2015-2426 high A remote code execution flaw in Windows' Adobe Type Manager Library allowed attackers to execute arbitrary code via specially crafted OpenType fonts.
2022-03-03 CVE-2002-0367 high A 2002 Windows privilege escalation flaw in smss.exe allowed local users to gain SYSTEM privileges without proper authentication.
2022-03-03 CVE-2004-0210 high A 20-year-old Windows privilege escalation flaw in the POSIX subsystem allows local users to gain full system control.
2022-03-03 CVE-2014-4114 high A 2014 Windows OLE remote code execution flaw was actively exploited in the wild, proving that years-old unpatched vulnerabilities remain a critical threat.
2022-03-03 CVE-2010-0232 high A 2010 Windows kernel flaw allowed local privilege escalation via unvalidated BIOS calls when 16-bit app support was enabled.
2022-02-10 CVE-2021-36934 high A Windows SAM local privilege escalation vulnerability allowed any user to read the SAM file and escalate to SYSTEM level if a Volume Shadow Copy was available.
2022-02-10 CVE-2017-8464 high A crafted .LNK file triggered remote code execution in Windows Shell, a flaw actively exploited in the wild and now on CISA's KEV list.
2021-11-03 CVE-2019-1214 high A privilege escalation vulnerability in the Windows CLFS driver was actively exploited in the wild, allowing attackers to escalate privileges without remote code execution.
2021-11-03 CVE-2019-0863 high A privilege escalation vulnerability in Windows Error Reporting allowed kernel-mode code execution, listed in CISA's KEV catalog as actively exploited.
2021-11-03 CVE-2016-0185 high A remote code execution flaw in Windows Media Center allowed attackers to execute arbitrary code via malicious .mcl files.
2021-11-03 CVE-2020-0601 high Microsoft Windows CryptoAPI spoofing vulnerability allowed attackers to use fake code-signing certificates to sign malicious executables and decrypt user connections.
2021-11-03 CVE-2020-1020 high A remote code execution flaw in Windows' Adobe Font Manager Library allowed attackers to execute arbitrary code on systems running Windows 10 and earlier.
2021-11-03 CVE-2021-33771 high An unpatched Windows kernel privilege escalation vulnerability was actively exploited in the wild, allowing attackers to escalate privileges without remote code execution.
2022-05-25 CVE-2015-1769 high Microsoft Windows Mount Manager improperly processes symbolic links, allowing privilege escalation.
2022-05-25 CVE-2015-6175 high A local privilege escalation vulnerability in the Windows kernel allowed attackers to gain elevated access via a crafted application.
2022-04-19 CVE-2022-22718 high An unpatched Windows Print Spooler privilege escalation vulnerability (CVE-2022-22718) was actively exploited in the wild, allowing attackers to escalate privileges on Windows systems.
2022-03-28 CVE-2021-34486 high A privilege escalation vulnerability in Windows Event Tracing was actively exploited in the wild, allowing attackers to escalate privileges without requiring remote code execution.
2022-03-25 CVE-2018-8414 high Microsoft Windows Shell remote code execution vulnerability allows attackers to execute arbitrary code via improper file path validation.
2021-11-03 CVE-2021-36948 high An unpatched privilege escalation flaw in Windows Update Medic Service was actively exploited in the wild, allowing attackers to escalate privileges on Windows systems.
Open questions: Why are critical vulnerabilities in Windows still actively exploited in 2026? · What is the root cause of repeated driver vulnerabilities in Windows?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 17:48:42.850246+00:00