Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27
Vulnerabilities
Page 115 of 141
CVE-2020-0939P4MEDIUMCVSS 5.5v1903v19092020-04-15
CVE-2020-0939 [MEDIUM] CVE-2020-0939: An information disclosure vulnerability exists when Media Foundation improperly handles objects in m
An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0937, CVE-2020-0945, CVE-2020-0946, CVE-2020-0947.
nvd
CVE-2021-34466P4MEDIUMCVSS 6.1v20h2v21h1+3 more2021-07-16
CVE-2021-34466 [MEDIUM] CWE-290 CVE-2021-34466: Windows Hello Security Feature Bypass Vulnerability
Windows Hello Security Feature Bypass Vulnerability
nvd
CVE-2022-35797P4MEDIUMCVSS 6.1v20h2v21h1+2 more2022-08-09
CVE-2022-35797 [MEDIUM] CVE-2022-35797: Windows Hello Security Feature Bypass Vulnerability
Windows Hello Security Feature Bypass Vulnerability
nvd
CVE-2021-42288P4MEDIUMCVSS 6.1v20h2v21h1+3 more2021-11-10
CVE-2021-42288 [MEDIUM] CVE-2021-42288: Windows Hello Security Feature Bypass Vulnerability
Windows Hello Security Feature Bypass Vulnerability
nvd
CVE-2020-1244P4HIGHCVSS 7.1v1809v1903+2 more2020-06-09
CVE-2020-1244 [HIGH] CVE-2020-1244: A denial of service vulnerability exists when Connected User Experiences and Telemetry Service impro
A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-1120.
nvd
CVE-2018-0885P4MEDIUMCVSS 5.8v1511v1607+2 more2018-03-14
CVE-2018-0885 [MEDIUM] CWE-20 CVE-2018-0885: The Microsoft Hyper-V Network Switch in 64-bit versions of Microsoft Windows Server 2008 SP2 and R2
The Microsoft Hyper-V Network Switch in 64-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows a denial of service vulnerability due to how input from a privileged user on a guest operating system is validated, a
nvd
CVE-2024-6768P4MEDIUMCVSS 6.8v10.0.02024-08-12
CVE-2024-6768 [MEDIUM] CWE-1284 CVE-2024-6768: A Denial of Service in CLFS.sys in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Se
A Denial of Service in CLFS.sys in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated low-privilege user to cause a Blue Screen of Death via a forced call to the KeBugCheckEx function.
nvd
CVE-2017-0179P4MEDIUMCVSS 5.8v1511v1607+1 more2017-04-12
CVE-2017-0179 [MEDIUM] CVE-2017-0179: A denial of service vulnerability exists when Microsoft Hyper-V running on a Windows 10, Windows 8.1
A denial of service vulnerability exists when Microsoft Hyper-V running on a Windows 10, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0182, CVE-2017-01
nvd
CVE-2020-1398P4MEDIUMCVSS 6.8v1607v1709+5 more2020-07-14
CVE-2020-1398 [MEDIUM] CVE-2020-1398: An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly handle Ease
An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly handle Ease of Access dialog.An attacker who successfully exploited the vulnerability could execute commands with elevated permissions.The security update addresses the vulnerability by ensuring that the Ease of Access dialog is handled properly., aka 'Windows Lockscreen
nvd
CVE-2020-17099P4MEDIUMCVSS 6.8v1607v1803+1 more2020-12-10
CVE-2020-17099 [MEDIUM] CVE-2020-17099: Windows Lock Screen Security Feature Bypass Vulnerability
Windows Lock Screen Security Feature Bypass Vulnerability
nvd
CVE-2020-0689P4MEDIUMCVSS 6.7v1607v1709+4 more2020-02-11
CVE-2020-0689 [MEDIUM] CVE-2020-0689: A security feature bypass vulnerability exists in secure boot, aka 'Microsoft Secure Boot Security F
A security feature bypass vulnerability exists in secure boot, aka 'Microsoft Secure Boot Security Feature Bypass Vulnerability'.
nvd
CVE-2020-1512P4MEDIUMCVSS 5.5v1607v1709+5 more2020-08-17
CVE-2020-1512 [MEDIUM] CVE-2020-1512: An information disclosure vulnerability exists when the Windows State Repository Service improperly
An information disclosure vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
An attacker could exploit this vulnerability by running a specially crafted application on the victim system.
T
nvd
CVE-2020-0904P4MEDIUMCVSS 6.5v1607v1709+5 more2020-09-11
CVE-2020-0904 [MEDIUM] CWE-20 CVE-2020-0904: <p>A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properl
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system.
To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application.
nvd
CVE-2017-8688P4MEDIUMCVSS 5.5v1511v1607+1 more2017-09-13
CVE-2017-8688 [MEDIUM] CVE-2017-8688: Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Se
Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows information disclosure by the way it discloses kernel memory addresses, aka "Windows GDI+ Information Disclosure Vulnerability". This CVE ID is unique
nvd
CVE-2019-1053P4MEDIUMCVSS 6.3v1607v1703+4 more2019-06-12
CVE-2019-1053 [MEDIUM] CWE-59 CVE-2019-1053: An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder short
An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the vulnerability could elevate privileges by escaping a sandbox.
To exploit this vulnerability, an attacker would require unprivileged execution on the victim system.
The security update addresses the vulnera
nvd
CVE-2022-21928P4MEDIUMCVSS 6.4v20h2v21h1+4 more2022-01-11
CVE-2022-21928 [MEDIUM] CVE-2022-21928: Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
nvd
CVE-2016-7258P4MEDIUMCVSS 5.5v1511v16072016-12-20
CVE-2016-7258 [MEDIUM] CWE-200 CVE-2016-7258: The kernel in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 mishandles page-faul
The kernel in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 mishandles page-fault system calls, which allows local users to obtain sensitive information from arbitrary processes via a crafted application, aka "Windows Kernel Memory Address Information Disclosure Vulnerability."
nvd
CVE-2021-1683P4MEDIUMCVSS 5.5v20h2v1607+4 more2021-01-12
CVE-2021-1683 [MEDIUM] CVE-2021-1683: Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For
Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG.
To address the vulnerability, Microsoft has released a software update that will fail attempts to pair if the remote device exchanges a public key with the same X coordinate
nvd
CVE-2021-1684P4MEDIUMCVSS 5.5v20h2v1607+4 more2021-01-12
CVE-2021-1684 [MEDIUM] CVE-2021-1684: Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For
Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG.
To address the vulnerability, Microsoft has released a software update that will fail attempts to pair if the remote device exchanges a public key with the same X coordinate
nvd
CVE-2018-8547P4MEDIUMCVSS 5.4v1607v1709+12 more2018-11-14
CVE-2018-8547 [MEDIUM] CWE-79 CVE-2018-8547: A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Ac
A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Federation Services (AD FS) does not properly sanitize a specially crafted web request to an affected AD FS server, aka "Active Directory Federation Services XSS Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows
nvd