Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27
Vulnerabilities
Page 11 of 141
CVE-2021-26432P2CRITICALCVSS 9.8v20h2v21h1+4 more2021-08-12
CVE-2021-26432 [CRITICAL] CVE-2021-26432: Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
nvd
CVE-2016-3216P3MEDIUMCVSS 4.3PoCv15112016-06-16
CVE-2016-3216 [MEDIUM] CWE-200 CVE-2016-3216: GDI32.dll in the Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 S
GDI32.dll in the Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "Windows Graphics Component Information Disclosure
nvd
CVE-2021-34535P2HIGHCVSS 8.8v20h2v21h1+4 more2021-08-12
CVE-2021-34535 [HIGH] CVE-2021-34535: Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2016-3368P2HIGHCVSS 8.8v1511v16072016-09-14
CVE-2016-3368 [HIGH] CWE-119 CVE-2016-3368: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow remote authenticated users to execute arbitrary code by leveraging a domain account to make a crafted request, aka "Windows Remote Code Execution Vulnerability."
nvd
CVE-2022-38044P3HIGHCVSS 7.8v20h2v21h1+3 more2022-10-11
CVE-2022-38044 [HIGH] CVE-2022-38044: Windows CD-ROM File System Driver Remote Code Execution Vulnerability
Windows CD-ROM File System Driver Remote Code Execution Vulnerability
nvd
CVE-2018-8495P3HIGHCVSS 7.5v1607v1703+10 more2018-10-10
CVE-2018-8495 [HIGH] CWE-22 CVE-2018-8495: A remote code execution vulnerability exists when Windows Shell improperly handles URIs, aka "Window
A remote code execution vulnerability exists when Windows Shell improperly handles URIs, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2019-0853P2HIGHCVSS 8.8v1607v1703+3 more2019-04-09
CVE-2019-0853 [HIGH] CWE-824 CVE-2019-0853: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2022-21849P2CRITICALCVSS 9.8v20h2v21h1+4 more2022-01-11
CVE-2022-21849 [CRITICAL] CVE-2022-21849: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2019-0603P3HIGHCVSS 7.5v1607v1803+1 more2019-04-08
CVE-2019-0603 [HIGH] CVE-2019-0603: A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server
A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system. To exploit the vulnerability, an attacker could create a specially crafted request, causing Windows to
nvd
CVE-2022-22012P2CRITICALCVSS 9.8v20h2v21h1+4 more2022-05-10
CVE-2022-22012 [CRITICAL] CVE-2022-22012: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29130P2CRITICALCVSS 9.8v20h2v21h1+4 more2022-05-10
CVE-2022-29130 [CRITICAL] CVE-2022-29130: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2021-34450P2CRITICALCVSS 9.9v20h2v21h1+3 more2021-07-16
CVE-2021-34450 [CRITICAL] CVE-2021-34450: Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2017-0118P3MEDIUMCVSS 4.3PoCv1511v16072017-03-17
CVE-2017-0118 [MEDIUM] CVE-2017-0118: Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerabili
nvd
CVE-2020-1436P2HIGHCVSS 8.8v1607v1709+5 more2020-07-14
CVE-2020-1436 [HIGH] CWE-787 CVE-2020-1436: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Windows Font Library Remote Code Execution Vulnerability'.
nvd
CVE-2021-43217P2CRITICALCVSS 9.8v20h2v21h1+4 more2021-12-15
CVE-2021-43217 [CRITICAL] CVE-2021-43217: Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
nvd
CVE-2016-3373P3MEDIUMCVSS 5.5PoCv1511v16072016-09-14
CVE-2016-3373 [MEDIUM] CWE-264 CVE-2016-3373: The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wi
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 does not properly implement registry access control, which allows local users to obtain sensitive account information via a crafted application, aka "Windows
nvd
CVE-2017-11779P3HIGHCVSS 8.1v1511v1607+1 more2017-10-13
CVE-2017-11779 [HIGH] CVE-2017-11779: The Microsoft Windows Domain Name System (DNS) DNSAPI.dll on Microsoft Windows 8.1, Windows Server 2
The Microsoft Windows Domain Name System (DNS) DNSAPI.dll on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly handle DNS responses, aka "Windows DNSAPI Remote Code Execution Vulnerability".
nvd
CVE-2015-6107P2CRITICALCVSS 9.3v15112015-12-09
CVE-2015-6107 [CRITICAL] CWE-119 CVE-2015-6107: The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10 Gold and 1511, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, Lync 2010, Lync 2013 SP1, and Live Meeting 2007 Console allows
nvd
CVE-2021-36965P2CRITICALCVSS 9.8v20h2v21h1+4 more2021-09-15
CVE-2021-36965 [CRITICAL] CVE-2021-36965: Windows WLAN AutoConfig Service Remote Code Execution Vulnerability
Windows WLAN AutoConfig Service Remote Code Execution Vulnerability
nvd
CVE-2017-0060P3MEDIUMCVSS 5.5PoCv1511v16072017-03-17
CVE-2017-0060 [MEDIUM] CWE-200 CVE-2017-0060: The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 S
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI+ Information Disclosure Vul
nvd