Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27
Vulnerabilities
Page 121 of 141
CVE-2020-16889P4MEDIUMCVSS 5.5v1607v1709+5 more2020-10-16
CVE-2020-16889 [MEDIUM] CVE-2020-16889: <p>An information disclosure vulnerability exists when the Windows KernelStream improperly handles o
An information disclosure vulnerability exists when the Windows KernelStream improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted applic
nvd
CVE-2020-1589P4MEDIUMCVSS 5.5v1607v1709+5 more2020-09-11
CVE-2020-1589 [MEDIUM] CVE-2020-1589: <p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. T
nvd
CVE-2019-1273P4MEDIUMCVSS 5.4v1803v1809+1 more2019-09-11
CVE-2019-1273 [MEDIUM] CWE-79 CVE-2019-1273: A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) d
A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize certain error messages, aka 'Active Directory Federation Services XSS Vulnerability'.
nvd
CVE-2020-16921P4MEDIUMCVSS 5.5v1709v1803+4 more2020-10-16
CVE-2020-16921 [MEDIUM] CVE-2020-16921: <p>An information disclosure vulnerability exists in Text Services Framework when it fails to proper
An information disclosure vulnerability exists in Text Services Framework when it fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could potentially read data that was not intended to be disclosed. Note that this vulnerability would not allow an attacker to execute code or to elevate their user rights dir
nvd
CVE-2020-16897P4MEDIUMCVSS 5.5v1607v1709+5 more2020-10-16
CVE-2020-16897 [MEDIUM] CVE-2020-16897: <p>An information disclosure vulnerability exists when NetBIOS over TCP (NBT) Extensions (NetBT) imp
An information disclosure vulnerability exists when NetBIOS over TCP (NBT) Extensions (NetBT) improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have run a specially crafted application. The vulnerabi
nvd
CVE-2020-16854P4MEDIUMCVSS 5.5v1607v1709+5 more2020-09-11
CVE-2020-16854 [MEDIUM] CVE-2020-16854: <p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.
nvd
CVE-2020-1548P4MEDIUMCVSS 5.5v1803v1809+3 more2020-08-17
CVE-2020-1548 [MEDIUM] CVE-2020-1548: An information disclosure vulnerability exists when the Windows WaasMedic Service improperly handles
An information disclosure vulnerability exists when the Windows WaasMedic Service improperly handles memory.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to improperly disclose memory.
The security update addresses the vulnerability by correcting
nvd
CVE-2017-8715P4MEDIUMCVSS 5.3v1511v1607+1 more2017-10-13
CVE-2017-8715 [MEDIUM] CVE-2017-8715: The Microsoft Device Guard on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 20
The Microsoft Device Guard on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass by the way it handles Windows PowerShell sessions, aka "Windows Security Feature Bypass".
nvd
CVE-2018-0854P4MEDIUMCVSS 5.3v1607v1703+11 more2018-05-09
CVE-2018-0854 [MEDIUM] CVE-2018-0854: A security feature bypass vulnerability exists in Windows Scripting Host which could allow an attack
A security feature bypass vulnerability exists in Windows Scripting Host which could allow an attacker to bypass Device Guard, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-0958, CVE-2018-8129, CVE-2018-8132.
nvd
CVE-2017-0216P4MEDIUMCVSS 5.3v1511v16072017-06-15
CVE-2017-0216 [MEDIUM] CVE-2017-0216: Microsoft Windows 10 1511, Windows 10 1607, and Windows Server 2016 allow an attacker to exploit a s
Microsoft Windows 10 1511, Windows 10 1607, and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerability in Device Guard that could allow the attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This CVE ID is unique from CVE-2017-01
nvd
CVE-2017-0173P4MEDIUMCVSS 5.3v16072017-06-15
CVE-2017-0173 [MEDIUM] CVE-2017-0173: Microsoft Windows 10 1607 and Windows Server 2016 allow an attacker to exploit a security feature by
Microsoft Windows 10 1607 and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerability in Device Guard that could allow the attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This CVE ID is unique from CVE-2017-0215, CVE-2017-0216,
nvd
CVE-2017-0219P4MEDIUMCVSS 5.3v1511v16072017-06-15
CVE-2017-0219 [MEDIUM] CVE-2017-0219: Microsoft Windows 10 Gold, Windows 10 1511, Windows 10 1607, and Windows Server 2016 allow an attack
Microsoft Windows 10 Gold, Windows 10 1511, Windows 10 1607, and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerability in Device Guard that could allow the attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This CVE ID is unique
nvd
CVE-2018-8204P4MEDIUMCVSS 5.3v1607v1703+2 more2018-08-15
CVE-2018-8204 [MEDIUM] CVE-2018-8204: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to injec
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8200.
nvd
CVE-2018-8200P4MEDIUMCVSS 5.3v1607v1703+12 more2018-08-15
CVE-2018-8200 [MEDIUM] CVE-2018-8200: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to injec
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8204.
nvd
CVE-2020-0989P4MEDIUMCVSS 5.5v1709v1803+4 more2020-09-11
CVE-2020-0989 [MEDIUM] CWE-862 CVE-2020-0989: <p>An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagno
An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions. An attacker who successfully exploited this vulnerability could bypass access restrictions to read files.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a
nvd
CVE-2017-8746P4MEDIUMCVSS 5.3v1607v17032017-09-13
CVE-2017-8746 [MEDIUM] CVE-2017-8746: Windows Device Guard in Windows 10 1607, 1703, and Windows Server 2016 allows A security feature byp
Windows Device Guard in Windows 10 1607, 1703, and Windows Server 2016 allows A security feature bypass vulnerability due to how PowerShell exposes functions and processes user supplied code, aka "Device Guard Security Feature Bypass Vulnerability".
nvd
CVE-2020-0805P4MEDIUMCVSS 5.5v20042020-09-11
CVE-2020-0805 [MEDIUM] CVE-2020-0805: <p>A security feature bypass vulnerability exists when a Windows Projected Filesystem improperly han
A security feature bypass vulnerability exists when a Windows Projected Filesystem improperly handles file redirections. An attacker who successfully exploited this vulnerability could delete a targeted file they would not have permissions to.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a spe
nvd
CVE-2019-0966P4MEDIUMCVSS 6.8v1607v1703+4 more2019-07-15
CVE-2019-0966 [MEDIUM] CWE-20 CVE-2019-0966: A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly v
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'.
nvd
CVE-2020-0661P4MEDIUMCVSS 6.8v1607v1809+1 more2020-02-11
CVE-2020-0661 [MEDIUM] CWE-20 CVE-2020-0661: A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly v
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-0751.
nvd
CVE-2020-0786P4HIGHCVSS 7.1v16072020-03-12
CVE-2020-0786 [HIGH] CVE-2020-0786: A denial of service vulnerability exists when the Windows Tile Object Service improperly handles har
A denial of service vulnerability exists when the Windows Tile Object Service improperly handles hard links, aka 'Windows Tile Object Service Denial of Service Vulnerability'.
nvd