Base OS XP 2003 Vista 2008 7 2008R2 8 8.1 2012 2012R2 10 2016
Service Pack SP0 SP1 SP2 SP3 SP0 SP1 SP2 SP0 SP1 SP2 SP0 SP2 SP0 SP1 SP0 SP1
MS03-026
MS05-039
MS08-025
MS08-067
MS08-068
MS09-012
MS09-050
MS10-015
MS10-059
MS10-092
MS11-011
MS11-046
MS11-062
MS11-080
MS13-005
MS13-053
MS13-081
MS14-002
MS14-040
MS14-058
MS14-062
MS14-068
MS14-070
MS15-001
MS15-010
MS15-051
MS15-061
MS15-076
MS15-078
MS15-097
MS16-016
MS16-032
MS16-135
MS17-010
CVE-2017-0213: COM Aggregate Marshaler
Hot Potato
SmashedPotato

<aside> 💡

This table does not go past 2017

</aside>

For detailed info: https://msrc.microsoft.com/update-guide/vulnerability

Check for spooler service

ls \\\\localhost\\pipe\\spoolss

Examining installed updates

systeminfo
wmic qfe list brief
Get-Hotfix

Viewing installed Updates with WMI

wmic qfe list brief

Writeup

Let’s test the CVE-2020-0668 example (https://itm4n.github.io/cve-2020-0668-windows-service-tracing-eop/)

  1. Check perms on mozilla maintenance service