Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27
Vulnerabilities
Page 108 of 141
CVE-2022-24498P4MEDIUMCVSS 6.5v20h2v21h1+4 more2022-04-15
CVE-2022-24498 [MEDIUM] CVE-2022-24498: Windows iSCSI Target Service Information Disclosure Vulnerability
Windows iSCSI Target Service Information Disclosure Vulnerability
nvd
CVE-2019-0707P4HIGHCVSS 7.0v1607v1703+4 more2019-05-16
CVE-2019-0707 [HIGH] CWE-787 CVE-2019-0707: An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS)
An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it.To exploit the vulnerability, in a local attack scenario, an attacker could run a specially crafted application to elevate the attacker's privilege level, aka 'Windows NDIS E
nvd
CVE-2019-0984P4HIGHCVSS 7.0v1607v1703+4 more2019-06-12
CVE-2019-0984 [HIGH] CVE-2019-0984: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted appli
nvd
CVE-2022-22717P4HIGHCVSS 7.0v20h2v21h1+4 more2022-02-09
CVE-2022-22717 [HIGH] CVE-2022-22717: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-21868P4HIGHCVSS 7.0v20h2v21h1+4 more2022-01-11
CVE-2022-21868 [HIGH] CVE-2022-21868: Windows Devices Human Interface Elevation of Privilege Vulnerability
Windows Devices Human Interface Elevation of Privilege Vulnerability
nvd
CVE-2022-21859P4HIGHCVSS 7.0v20h2v21h1+3 more2022-01-11
CVE-2022-21859 [HIGH] CVE-2022-21859: Windows Accounts Control Elevation of Privilege Vulnerability
Windows Accounts Control Elevation of Privilege Vulnerability
nvd
CVE-2022-29126P4HIGHCVSS 7.0v20h2v21h1+4 more2022-05-10
CVE-2022-29126 [HIGH] CVE-2022-29126: Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability
Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability
nvd
CVE-2022-21866P4HIGHCVSS 7.0v20h2v21h1+4 more2022-01-11
CVE-2022-21866 [HIGH] CVE-2022-21866: Windows System Launcher Elevation of Privilege Vulnerability
Windows System Launcher Elevation of Privilege Vulnerability
nvd
CVE-2022-22016P4HIGHCVSS 7.0v20h2v21h1+4 more2022-05-10
CVE-2022-22016 [HIGH] CVE-2022-22016: Windows PlayToManager Elevation of Privilege Vulnerability
Windows PlayToManager Elevation of Privilege Vulnerability
nvd
CVE-2022-22036P4HIGHCVSS 7.0v20h2v21h1+3 more2022-07-12
CVE-2022-22036 [HIGH] CVE-2022-22036: Performance Counters for Windows Elevation of Privilege Vulnerability
Performance Counters for Windows Elevation of Privilege Vulnerability
nvd
CVE-2022-30224P4HIGHCVSS 7.0v20h2v21h1+3 more2022-07-12
CVE-2022-30224 [HIGH] CVE-2022-30224: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
nvd
CVE-2022-41114P4HIGHCVSS 7.0v20h2v21h1+2 more2022-11-09
CVE-2022-41114 [HIGH] CWE-362 CVE-2022-41114: Windows Bind Filter Driver Elevation of Privilege Vulnerability
Windows Bind Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-21771P4HIGHCVSS 7.0v20h2v21h2+1 more2023-01-10
CVE-2023-21771 [HIGH] CWE-591 CVE-2023-21771: Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability
Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability
nvd
CVE-2022-38021P4HIGHCVSS 7.0v20h2v21h1+3 more2022-10-11
CVE-2022-38021 [HIGH] CWE-362 CVE-2022-38021: Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
nvd
CVE-2019-0986P4MEDIUMCVSS 6.3v1607v1703+4 more2019-06-12
CVE-2019-0986 [MEDIUM] CWE-59 CVE-2019-0986: An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) impro
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a spe
nvd
CVE-2023-21694P4MEDIUMCVSS 6.8fixed in 10.0.10240.197472023-02-14
CVE-2023-21694 [MEDIUM] CWE-122 CVE-2023-21694: Windows Fax Service Remote Code Execution Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2020-15706P4MEDIUMCVSS 6.4v1607v1709+5 more2020-07-29
CVE-2020-15706 [MEDIUM] CWE-362 CVE-2020-15706: GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnera
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.
nvd
CVE-2017-8587P4MEDIUMCVSS 6.5v15112017-07-11
CVE-2017-8587 [MEDIUM] CVE-2017-8587: Windows Explorer in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2
Windows Explorer in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511 allows a denial of service vulnerability when it attempts to open a non-existent file, aka "Windows Explorer Denial of Service Vulnerability".
nvd
CVE-2017-8673P4MEDIUMCVSS 5.9v17032017-08-08
CVE-2017-8673 [MEDIUM] CVE-2017-8673: The Remote Desktop Protocol (RDP) implementation in Microsoft Windows 10 1703 allows an attacker to
The Remote Desktop Protocol (RDP) implementation in Microsoft Windows 10 1703 allows an attacker to connect to a target system using RDP and send specially crafted requests, aka "Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability."
nvd
CVE-2022-24460P4HIGHCVSS 7.0v20h2v21h1+4 more2022-03-09
CVE-2022-24460 [HIGH] CVE-2022-24460: Tablet Windows User Interface Application Elevation of Privilege Vulnerability
Tablet Windows User Interface Application Elevation of Privilege Vulnerability
nvd