Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27
Vulnerabilities
Page 113 of 141
CVE-2019-1416P4HIGHCVSS 7.0v1709v1803+2 more2019-11-12
CVE-2019-1416 [HIGH] CWE-362 CVE-2019-1416: An elevation of privilege vulnerability exists due to a race condition in Windows Subsystem for Linu
An elevation of privilege vulnerability exists due to a race condition in Windows Subsystem for Linux, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1324P4MEDIUMCVSS 5.3v1709v1803+2 more2019-11-12
CVE-2019-1324 [MEDIUM] CWE-200 CVE-2019-1324: An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles IPv6
An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles IPv6 flowlabel filled in packets, aka 'Windows TCP/IP Information Disclosure Vulnerability'.
nvd
CVE-2021-34493P4MEDIUMCVSS 6.7v20h2v21h1+4 more2021-07-14
CVE-2021-34493 [MEDIUM] CWE-269 CVE-2021-34493: Windows Partition Management Driver Elevation of Privilege Vulnerability
Windows Partition Management Driver Elevation of Privilege Vulnerability
nvd
CVE-2021-41338P4MEDIUMCVSS 5.5v20h2v21h1+4 more2021-10-13
CVE-2021-41338 [MEDIUM] CVE-2021-41338: Windows AppContainer Firewall Rules Security Feature Bypass Vulnerability
Windows AppContainer Firewall Rules Security Feature Bypass Vulnerability
nvd
CVE-2022-34709P4MEDIUMCVSS 6.0v20h2v21h1+3 more2022-08-09
CVE-2022-34709 [MEDIUM] CWE-843 CVE-2022-34709: Windows Defender Credential Guard Security Feature Bypass Vulnerability
Windows Defender Credential Guard Security Feature Bypass Vulnerability
nvd
CVE-2019-1470P4MEDIUMCVSS 6.0v1607v1709+4 more2019-12-10
CVE-2019-1470 [MEDIUM] CWE-20 CVE-2019-1470: An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.
nvd
CVE-2020-16919P4MEDIUMCVSS 5.5v1607v1709+5 more2020-10-16
CVE-2020-16919 [MEDIUM] CVE-2020-16919: <p>An information disclosure vulnerability exists when the Windows Enterprise App Management Service
An information disclosure vulnerability exists when the Windows Enterprise App Management Service improperly handles certain file operations. An attacker who successfully exploited this vulnerability could read arbitrary files.
An attacker with unprivileged access to a vulnerable system could exploit this vulnerability.
The security update addresses the vul
nvd
CVE-2022-30154P4MEDIUMCVSS 5.3v20h22022-06-15
CVE-2022-30154 [MEDIUM] CVE-2022-30154: Microsoft File Server Shadow Copy Agent Service (RVSS) Elevation of Privilege Vulnerability
Microsoft File Server Shadow Copy Agent Service (RVSS) Elevation of Privilege Vulnerability
nvd
CVE-2017-0191P4MEDIUMCVSS 5.8v1511v1607+1 more2017-04-12
CVE-2017-0191 [MEDIUM] CVE-2017-0191: A denial of service vulnerability exists in the way that Windows 7, Windows 8.1, Windows 10, Windows
A denial of service vulnerability exists in the way that Windows 7, Windows 8.1, Windows 10, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding, aka "Windows Denial of Service Vulnerabilit
nvd
CVE-2017-0186P4MEDIUMCVSS 5.8v1511v1607+1 more2017-04-12
CVE-2017-0186 [MEDIUM] CVE-2017-0186: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-20
nvd
CVE-2017-0182P4MEDIUMCVSS 5.8v1511v1607+1 more2017-04-12
CVE-2017-0182 [MEDIUM] CVE-2017-0182: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE
nvd
CVE-2019-0716P4MEDIUMCVSS 5.8v1607v1703+4 more2019-08-14
CVE-2019-0716 [MEDIUM] CVE-2019-0716: A denial of service vulnerability exists when Windows improperly handles objects in memory. An attac
A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an
nvd
CVE-2017-0183P4MEDIUMCVSS 5.8v1511v1607+1 more2017-04-12
CVE-2017-0183 [MEDIUM] CVE-2017-0183: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE
nvd
CVE-2019-0886P4MEDIUMCVSS 6.8v1607v1703+4 more2019-05-16
CVE-2019-0886 [MEDIUM] CWE-20 CVE-2019-0886: An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.
nvd
CVE-2021-40463P4MEDIUMCVSS 6.5v20h2v21h1+4 more2021-10-13
CVE-2021-40463 [MEDIUM] CVE-2021-40463: Windows Network Address Translation (NAT) Denial of Service Vulnerability
Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2020-0730P4HIGHCVSS 7.1v1607v1709+4 more2020-02-11
CVE-2020-0730 [HIGH] CWE-59 CVE-2020-0730: An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) impro
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.
nvd
CVE-2018-0881P4HIGHCVSS 7.0v1511v1607+2 more2018-03-14
CVE-2018-0881 [HIGH] CVE-2018-0881: The Microsoft Video Control in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1 and
The Microsoft Video Control in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege due to how objects are handled in memory, aka "Microsoft Video Control Elevation of Privilege Vul
nvd
CVE-2018-8167P4HIGHCVSS 7.0v1607v1703+12 more2018-05-09
CVE-2018-8167 [HIGH] CWE-404 CVE-2018-8167: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka "Windows Common Log File System Driver Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server
nvd
CVE-2020-1510P4MEDIUMCVSS 5.5v1607v1709+5 more2020-08-17
CVE-2020-1510 [MEDIUM] CWE-200 CVE-2020-1510: An information disclosure vulnerability exists when the win32k component improperly provides kernel
An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted appl
nvd
CVE-2020-0936P4HIGHCVSS 7.1v1607v1709+4 more2020-04-15
CVE-2020-0936 [HIGH] CVE-2020-0936: An elevation of privilege vulnerability exists when a Windows scheduled task improperly handles file
An elevation of privilege vulnerability exists when a Windows scheduled task improperly handles file redirections, aka 'Windows Scheduled Task Elevation of Privilege Vulnerability'.
nvd