Microsoft Corporation

First CVE: Apr 12, 2005Active for: 21 years
12,990
CVEs Published
More CVEs Published than 99% of tracked CNAs
590.5
Avg CVEs / Year
More Avg CVEs / Year than 98% of tracked CNAs
7.4
Avg CVSS Score
Higher Avg CVSS Score than 64% of tracked CNAs
2.9%
In CISA KEV
Higher KEV Rate than 94% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Microsoft Corporation as a CNA, 99.6% affect products that Microsoft Corporation develops as a vendor.

99.6%
Self-reported: 12,944Third-party: 46

Of all the CVEs published that affect products developed by Microsoft Corporation, 50.6% are self-published by Microsoft Corporation as a CNA.

50.6%
49.4%
Self-published: 12,944Published by other CNAs: 12,636

Trends Over Time

The number and severity of CVEs published by Microsoft Corporation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 12, 2005
21 years ago
Most Recent CVE
Jul 17, 2026
7 days ago

Top CVEs

All CVEs published by Microsoft Corporation as a CNA, regardless of affected vendor or product.

12,990 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
Oct 14, 20259.899YESYES
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for
Jul 20, 20259.899YESYES
Microsoft Exchange Server Remote Code Execution Vulnerability
Mar 3, 20219.899YESYES
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protoc
Aug 17, 202010.099YESYES
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Re
Mar 12, 202010.099YESYES
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remo
Feb 11, 20208.899YESYES
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.
Jan 14, 20209.899YESYES
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP
May 16, 20199.899YESYES
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via c
Apr 14, 20159.899YESYES
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Jul 8, 20256.598YESYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA12,990 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local5,429 (41.8%)
Network4,862 (37.4%)
Unknown2,256 (17.4%)
Physical181 (1.4%)
Adjacent Network262 (2.0%)
Attack Complexity
Low8,652 (66.6%)
High2,082 (16.0%)
Unknown2,256 (17.4%)
User Interaction
None6,420 (49.4%)
Unknown2,256 (17.4%)
Required4,314 (33.2%)
Privileges Required
Low4,972 (38.3%)
High426 (3.3%)
None5,336 (41.1%)
Unknown2,256 (17.4%)

Exploit Exposure

Signals from CVEs in this cna scope (12990 CVEs).

CISA KEV
373 CVEs
2.9% of CVEs· 94th percentile
Metasploit
205 CVEs
1.6% of CVEs· 90th percentile
Nuclei
21 CVEs
0.2% of CVEs· 71st percentile
ExploitDB
939 CVEs
7.2% of CVEs· 97th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Microsoft Corporation as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Microsoft Corporation as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs