Windows 8
Vendor:
First CVE: May 9, 2012 · Active for 14 years
324
Total CVEs
More Total CVEs than 100% of tracked products
36.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
9.9%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Windows 8 over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 9, 2012
14 years ago
Most Recent CVE
Jun 30, 2020
2,215 days ago
CVE Severity & Scoring
Windows 8324 CVEs
19%
71%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local28 (8.6%)
Network45 (13.9%)
Unknown250 (77.2%)
Physical1 (0.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low69 (21.3%)
High5 (1.5%)
Unknown250 (77.2%)
User Interaction
None32 (9.9%)
Unknown250 (77.2%)
Required42 (13.0%)
Privileges Required
Low19 (5.9%)
High3 (0.9%)
None52 (16.0%)
Unknown250 (77.2%)
Top CVEs
Signals from CVEs in this product scope (324 CVEs).
324 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-1635CRITICAL HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via c | Apr 14, 2015 | 9.8 | 99 | YES | YES |
CVE-2015-5122CRITICAL Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 1 | Jul 14, 2015 | 9.8 | 98 | YES | YES |
CVE-2015-0313CRITICAL Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote atta | Feb 2, 2015 | 9.8 | 98 | YES | YES |
CVE-2014-6332HIGH OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and | Nov 11, 2014 | 8.8 | 98 | YES | YES |
CVE-2015-2426HIGH Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, W | Jul 20, 2015 | 8.8 | 97 | YES | YES |
CVE-2015-0311CRITICAL Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote a | Jan 23, 2015 | 9.8 | 97 | YES | YES |
CVE-2014-6324HIGH The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and W | Nov 18, 2014 | 8.8 | 97 | YES | YES |
CVE-2014-4114HIGH Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote at | Oct 15, 2014 | 7.8 | 97 | YES | YES |
CVE-2014-4113HIGH win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Se | Oct 15, 2014 | 7.8 | 97 | YES | YES |
CVE-2014-0322HIGH Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and t | Feb 14, 2014 | 8.8 | 97 | YES | YES |
Exploit Exposure
Signals from CVEs in this product scope (324 CVEs).
CISA KEV
32 CVEs
9.9% of CVEs· 97th percentile
Metasploit
31 CVEs
9.6% of CVEs· 97th percentile
Nuclei
1 CVE
0.3% of CVEs· 96th percentile
ExploitDB
97 CVEs
29.9% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (324 CVEs).
Media Mentions
Signals from CVEs in this product scope (324 CVEs).
Top CNAs Publishing CVEs For Windows 8
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| consumer_preview | 1 | 9.3 | 27.0% | 0 | 0 |