The Microsoft Windows operating system maintains a desktop market share of approximately 70% as of December 2024, yet Windows-specific vulnerability research remains underrepresented in peer-reviewed venues despite its practical importance. This paper presents a Systematization of Knowledge (SoK) of the Windows vulnerability research landscape. We propose an attack-tree-based taxonomy that organizes Windows attack surfaces into a principled hierarchy, where each level uses a single classification axis (attacker prerequisite, target privilege boundary, and specific component), with orthogonal annotations for root cause, research barrier, and ecosystem affinity. It explains which attack surfaces exist and why certain surfaces attract or repel specific research communities. Our study triangulates evidence from a systematic review of 112 papers, root-cause analysis of 382 CVEs with public exploit code spanning 40 attack-surface components, semi-structured expert interviews ( n =5), and a practitioner survey ( n =17). We identify three separable structural causes of the research-practice gap: deployment friction, incentive misalignment, and data opacity. Cross-referencing practitioner-assessed importance with academic publication coverage, we produce a prioritized list of underexplored surfaces (COM, CLFS, cloud-hosted Windows environments, and RDP) with concrete methodological entry points for future work. We release the curated dataset and classification artifacts to support replication and follow-on studies.
Tian et al. (Wed,) studied this question.