Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27
Vulnerabilities
Page 114 of 141
CVE-2017-8702P4HIGHCVSS 7.0v1511v16072017-09-13
CVE-2017-8702 [HIGH] CVE-2017-8702: Windows Error Reporting (WER) in Microsoft Windows 10 Gold, 1511, and 1607, and Windows Server 2016
Windows Error Reporting (WER) in Microsoft Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows an attacker to gain greater access to sensitive information and system functionality, due to the way that WER handles and executes files, aka "Windows Elevation of Privilege Vulnerability".
nvd
CVE-2017-8566P4HIGHCVSS 7.0v1607v17032017-07-11
CVE-2017-8566 [HIGH] CWE-20 CVE-2017-8566: Microsoft Windows 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability
Microsoft Windows 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Windows Input Method Editor (IME) improperly handling parameters in a method of a DCOM class, aka "Windows IME Elevation of Privilege Vulnerability".
nvd
CVE-2017-8574P4HIGHCVSS 7.0v1607v17032017-07-11
CVE-2017-8574 [HIGH] CVE-2017-8574: Graphics in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an elevation of privileg
Graphics in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Microsoft Graphics Component Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8573 and CVE-2017-8556.
nvd
CVE-2020-0785P4HIGHCVSS 7.1v1607v1709+4 more2020-03-12
CVE-2020-0785 [HIGH] CWE-269 CVE-2020-0785: An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) impro
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.
nvd
CVE-2017-8562P4HIGHCVSS 7.0v1511v1607+1 more2017-07-11
CVE-2017-8562 [HIGH] CWE-281 CVE-2017-8562: Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, a
Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Windows improperly handling calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability".
nvd
CVE-2020-0918P4MEDIUMCVSS 6.8v1809v1903+1 more2020-04-15
CVE-2020-0918 [MEDIUM] CVE-2020-0918: An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to proper
An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0917.
nvd
CVE-2020-1459P4MEDIUMCVSS 5.5v1809v1903+2 more2020-08-17
CVE-2020-1459 [MEDIUM] CWE-203 CVE-2020-1459: An information disclosure vulnerability exists on ARM implementations that use speculative execution
An information disclosure vulnerability exists on ARM implementations that use speculative execution in control flow via a side-channel analysis, aka "straight-line speculation."
To exploit this vulnerability, an attacker with local privileges would need to run a specially crafted application.
The security update addresses the vulnerability by bypassi
nvd
CVE-2022-21960P4MEDIUMCVSS 6.8v20h2v21h1+4 more2022-01-11
CVE-2022-21960 [MEDIUM] CVE-2022-21960: Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
nvd
CVE-2022-21959P4MEDIUMCVSS 6.8v20h2v21h1+4 more2022-01-11
CVE-2022-21959 [MEDIUM] CVE-2022-21959: Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
nvd
CVE-2022-21892P4MEDIUMCVSS 6.8v20h2v21h1+4 more2022-01-11
CVE-2022-21892 [MEDIUM] CVE-2022-21892: Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
nvd
CVE-2022-21958P4MEDIUMCVSS 6.8v20h2v21h1+4 more2022-01-11
CVE-2022-21958 [MEDIUM] CVE-2022-21958: Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
nvd
CVE-2022-21961P4MEDIUMCVSS 6.8v20h2v21h1+4 more2022-01-11
CVE-2022-21961 [MEDIUM] CVE-2022-21961: Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
nvd
CVE-2022-21962P4MEDIUMCVSS 6.8v20h2v21h1+4 more2022-01-11
CVE-2022-21962 [MEDIUM] CVE-2022-21962: Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
nvd
CVE-2022-21963P4MEDIUMCVSS 6.8v20h2v21h1+4 more2022-01-11
CVE-2022-21963 [MEDIUM] CVE-2022-21963: Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
nvd
CVE-2017-11829P4MEDIUMCVSS 5.5v1607v17032017-10-13
CVE-2017-11829 [MEDIUM] CWE-552 CVE-2017-11829: Microsoft Windows 10 allows an elevation of privilege vulnerability when the Windows Update Delivery
Microsoft Windows 10 allows an elevation of privilege vulnerability when the Windows Update Delivery Optimization does not properly enforce file share permissions.
nvd
CVE-2016-3320P4MEDIUMCVSS 4.9v15112016-08-09
CVE-2016-3320 [MEDIUM] CWE-254 CVE-2016-3320: Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow attackers to bypass the Secure Boot protection mechanism by leveraging (1) administrative or (2) physical access to install a crafted boot manager, aka "Secure Boot Security Feature Bypass."
nvd
CVE-2022-38032P4MEDIUMCVSS 6.6v20h2v21h1+3 more2022-10-11
CVE-2022-38032 [MEDIUM] CVE-2022-38032: Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability
Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability
nvd
CVE-2022-22023P4MEDIUMCVSS 6.6v20h2v21h1+3 more2022-07-12
CVE-2022-22023 [MEDIUM] CVE-2022-22023: Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability
Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability
nvd
CVE-2016-7223P4MEDIUMCVSS 6.1v1511v16072016-11-10
CVE-2016-7223 [MEDIUM] CWE-284 CVE-2016-7223: Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,
Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability."
nvd
CVE-2020-16910P4MEDIUMCVSS 5.5v1607v1709+5 more2020-10-16
CVE-2020-16910 [MEDIUM] CWE-281 CVE-2020-16910: <p>A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creati
A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location.
To exploit this vulnerability, an attacker could run a specially crafted application to bypass Unified Extensible Firmware
nvd