Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
216
Exploited in wild
26
Severity breakdown
CRITICAL68HIGH1907MEDIUM802LOW27

Vulnerabilities

Page 123 of 141
CVE-2017-8709MEDIUMCVSS 4.7v1511v1607+1 more2017-09-13
CVE-2017-8709 [MEDIUM] CVE-2017-8709: The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnera
nvd
CVE-2017-8688MEDIUMCVSS 5.5v1511v1607+1 more2017-09-13
CVE-2017-8688 [MEDIUM] CVE-2017-8688: Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Se Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows information disclosure by the way it discloses kernel memory addresses, aka "Windows GDI+ Information Disclosure Vulnerability". This CVE ID is unique
nvd
CVE-2017-8683MEDIUMCVSS 5.5PoCv1511v1607+1 more2017-09-13
CVE-2017-8683 [MEDIUM] CVE-2017-8683: Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows an attacker to execute remote code by the way it handles embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability". This CVE ID is
nvd
CVE-2017-8711MEDIUMCVSS 5.3v16072017-09-13
CVE-2017-8711 [MEDIUM] CVE-2017-8711: The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows an informa The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8707, CVE-2017-8706, CVE-2017-8712, and CVE-20
nvd
CVE-2017-8708MEDIUMCVSS 4.7PoCv1511v1607+1 more2017-09-13
CVE-2017-8708 [MEDIUM] CVE-2017-8708: The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnera
nvd
CVE-2017-8713MEDIUMCVSS 5.3v1511v1607+1 more2017-09-13
CVE-2017-8713 [MEDIUM] CVE-2017-8713: The Windows Hyper-V component on Microsoft Windows Windows 8.1, Windows Server 2012 Gold and R2, Win The Windows Hyper-V component on Microsoft Windows Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability". This
nvd
CVE-2017-8746MEDIUMCVSS 5.3v1607v17032017-09-13
CVE-2017-8746 [MEDIUM] CVE-2017-8746: Windows Device Guard in Windows 10 1607, 1703, and Windows Server 2016 allows A security feature byp Windows Device Guard in Windows 10 1607, 1703, and Windows Server 2016 allows A security feature bypass vulnerability due to how PowerShell exposes functions and processes user supplied code, aka "Device Guard Security Feature Bypass Vulnerability".
nvd
CVE-2017-8704MEDIUMCVSS 5.3v16072017-09-13
CVE-2017-8704 [MEDIUM] CWE-20 CVE-2017-8704: The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows a denial o The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows a denial of service vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability".
nvd
CVE-2017-8679MEDIUMCVSS 5.5v1511v1607+1 more2017-09-13
CVE-2017-8679 [MEDIUM] CWE-200 CVE-2017-8679: The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Windows Kernel Information Disclosure
nvd
CVE-2017-8716MEDIUMCVSS 5.3v17032017-09-13
CVE-2017-8716 [MEDIUM] CVE-2017-8716: Windows Control Flow Guard in Microsoft Windows 10 Version 1703 allows an attacker to run a speciall Windows Control Flow Guard in Microsoft Windows 10 Version 1703 allows an attacker to run a specially crafted application to bypass Control Flow Guard, due to the way that Control Flow Guard handles objects in memory, aka "Windows Security Feature Bypass Vulnerability".
nvd
CVE-2017-8695MEDIUMCVSS 5.3v1511v1607+1 more2017-09-13
CVE-2017-8695 [MEDIUM] CWE-200 CVE-2017-8695: Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windo Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, 1607, 1703, and Server 2016; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live
nvd
CVE-2017-8681MEDIUMCVSS 5.5PoCv1511v1607+1 more2017-09-13
CVE-2017-8681 [MEDIUM] CVE-2017-8681: The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Win32k Information Disclosure Vulnerability".
nvd
CVE-2017-8706MEDIUMCVSS 5.3v1511v1607+1 more2017-09-13
CVE-2017-8706 [MEDIUM] CWE-200 CVE-2017-8706: The Windows Hyper-V component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server The Windows Hyper-V component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8707, CVE-2017-
nvd
CVE-2017-8676LOWCVSS 3.3v1511v1607+1 more2017-09-13
CVE-2017-8676 [LOW] CWE-200 CVE-2017-8676: The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, 1607, 1703, and Server 2016; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2
nvd
CVE-2017-8620HIGHCVSS 8.1v1511v1607+1 more2017-08-08
CVE-2017-8620 [HIGH] CWE-119 CVE-2017-8620: Windows Search in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 201 Windows Search in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it improperly handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability".
nvd
CVE-2017-0250HIGHCVSS 7.8v1511v1607+1 more2017-08-08
CVE-2017-0250 [HIGH] CWE-119 CVE-2017-0250: Microsoft JET Database Engine in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Win Microsoft JET Database Engine in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to buffer overflow, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability".
nvd
CVE-2017-8622HIGHCVSS 7.8v17032017-08-08
CVE-2017-8622 [HIGH] CVE-2017-8622: Windows Subsystem for Linux in Windows 10 1703 allows an elevation of privilege vulnerability when i Windows Subsystem for Linux in Windows 10 1703 allows an elevation of privilege vulnerability when it fails to properly handle handles NT pipes, aka "Windows Subsystem for Linux Elevation of Privilege Vulnerability".
nvd
CVE-2017-8664HIGHCVSS 8.8v1511v1607+1 more2017-08-08
CVE-2017-8664 [HIGH] CWE-20 CVE-2017-8664: Windows Hyper-V in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 15 Windows Hyper-V in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability".
nvd
CVE-2017-8624HIGHCVSS 7.8v1511v1607+1 more2017-08-08
CVE-2017-8624 [HIGH] CVE-2017-8624: CLFS in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and CLFS in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way it handles objects in memory, aka "Windows CLFS Elevation of Privilege Vulnerability".
nvd
CVE-2017-8591HIGHCVSS 7.8v1511v1607+1 more2017-08-08
CVE-2017-8591 [HIGH] CVE-2017-8591: Windows Input Method Editor (IME) in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, W Windows Input Method Editor (IME) in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an remote code execution vulnerability when it fails to properly handle objects in memory, aka "Windows IME Remote Code Execution Vulnerability".
nvd