Are there known vulnerabilities exist on Windows that are not patched?

https://lemmy.world/post/415356

Are there known vulnerabilities exist on Windows that are not patched? - Lemmy.world

I only know about CVE-2013-3900 [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2013-3900] (WinVerifyTrust) which allows modified files to pass signature check unless you tweak registry to enable patches. I think there must be other instances like this where Microsoft won’t fix vulnerability or chooses insecure defaults, is there a list?

A fair number of vulnerabilities exist where a patch or mitigation exists, but hasn't been widely applied for various reasons.