cbcvebase.

Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27

Vulnerabilities

Page 15 of 141
CVE-2017-0211P3MEDIUMCVSS 5.5PoCv1511v1607+1 more2017-04-12
CVE-2017-0211 [MEDIUM] CWE-610 CVE-2017-0211: An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows S An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 versions of Microsoft Windows OLE when it fails an integrity-level check, aka "Windows OLE Elevation of Privilege Vulnerability."
nvd
CVE-2020-0881P3HIGHCVSS 8.8v1607v1709+4 more2020-03-12
CVE-2020-0881 [HIGH] CVE-2020-0881: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0883.
nvd
CVE-2019-0790P3HIGHCVSS 8.8v1607v1703+3 more2019-04-09
CVE-2019-0790 [HIGH] CWE-611 CVE-2019-0790: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0791, CVE-2019-0792, CVE-2019-0793, CVE-2019-0795.
nvd
CVE-2017-8565P3HIGHCVSS 8.1v1511v1607+1 more2017-07-11
CVE-2017-8565 [HIGH] CVE-2017-8565: Windows PowerShell in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server Windows PowerShell in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability when PSObject wraps a CIM Instance, aka "Windows PowerShell Remote Code Execution Vulnerability".
nvd
CVE-2018-0880P3HIGHCVSS 7.0PoCv1607v1703+1 more2018-03-14
CVE-2018-0880 [HIGH] CVE-2018-0880: The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, versi The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how the virtual registry is managed, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0882.
nvd
CVE-2016-7217P3HIGHCVSS 8.8v1511v16072016-11-10
CVE-2016-7217 [HIGH] CWE-119 CVE-2016-7217: Media Foundation in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows Media Foundation in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Media Foundation Memory Corruption Vulnerability."
nvd
CVE-2019-0794P3HIGHCVSS 8.8v1607v1703+3 more2019-04-09
CVE-2019-0794 [HIGH] CVE-2019-0794: A remote code execution vulnerability exists when OLE automation improperly handles objects in memor A remote code execution vulnerability exists when OLE automation improperly handles objects in memory, aka 'OLE Automation Remote Code Execution Vulnerability'.
nvd
CVE-2018-0882P3HIGHCVSS 7.0PoCv1607v1703+1 more2018-03-14
CVE-2018-0882 [HIGH] CVE-2018-0882: The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, versi The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how the virtual registry is managed, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0880.
nvd
CVE-2018-0743P3HIGHCVSS 7.0PoCv1703v17092018-01-04
CVE-2018-0743 [HIGH] CVE-2018-0743: Windows Subsystem for Linux in Windows 10 version 1703, Windows 10 version 1709, and Windows Server, Windows Subsystem for Linux in Windows 10 version 1703, Windows 10 version 1709, and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Subsystem for Linux Elevation of Privilege Vulnerability".
nvd
CVE-2019-1212P3CRITICALCVSS 9.8v1607v1709+3 more2019-08-14
CVE-2019-1212 [CRITICAL] CWE-787 CVE-2019-1212: A memory corruption vulnerability exists in the Windows Server DHCP service when processing speciall A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets. An attacker who successfully exploited the vulnerability could cause the DHCP server service to stop responding. To exploit the vulnerability, a remote unauthenticated attacker could send a specially crafted packet to an affected DH
nvd
CVE-2018-0823P3HIGHCVSS 7.0PoCv17092018-02-15
CVE-2018-0823 [HIGH] CVE-2018-0823: The Named Pipe File System in Windows 10 version 1709 and Windows Server, version 1709 allows an ele The Named Pipe File System in Windows 10 version 1709 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way the Named Pipe File System handles objects, aka "Named Pipe File System Elevation of Privilege Vulnerability".
nvd
CVE-2019-0845P3HIGHCVSS 8.8v1607v1703+3 more2019-04-09
CVE-2019-0845 [HIGH] CVE-2019-0845: A remote code execution vulnerability exists when the IOleCvt interface renders ASP webpage content, A remote code execution vulnerability exists when the IOleCvt interface renders ASP webpage content, aka 'Windows IOleCvt Interface Remote Code Execution Vulnerability'.
nvd
CVE-2020-1281P3HIGHCVSS 8.8v1607v1709+5 more2020-06-09
CVE-2020-1281 [HIGH] CWE-190 CVE-2020-1281: A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate u A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.
nvd
CVE-2016-7225P3MEDIUMCVSS 6.1PoCv1511v16072016-11-10
CVE-2016-7225 [MEDIUM] CWE-284 CVE-2016-7225: Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properl Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability."
nvd
CVE-2016-7224P3MEDIUMCVSS 6.1PoCv1511v16072016-11-10
CVE-2016-7224 [MEDIUM] CWE-284 CVE-2016-7224: Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability."
nvd
CVE-2016-7226P3MEDIUMCVSS 6.1PoCv1511v16072016-11-10
CVE-2016-7226 [MEDIUM] CWE-284 CVE-2016-7226: Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properl Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability."
nvd
CVE-2016-0070P3MEDIUMCVSS 5.5PoCv1511v16072016-10-14
CVE-2016-0070 [MEDIUM] CWE-200 CVE-2016-0070: The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, aka "Windows Kernel Local
nvd
CVE-2020-0662P3HIGHCVSS 8.8v1607v1709+4 more2020-02-11
CVE-2020-0662 [HIGH] CVE-2020-0662: A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.
nvd
CVE-2019-1365P3CRITICALCVSS 9.9v1607v1803+2 more2019-10-10
CVE-2019-1365 [CRITICAL] CVE-2019-1365: An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length o An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the context of NT AUTHORITY\system escaping the Sandbox.The security update addresses the
nvd
CVE-2017-0023P3HIGHCVSS 7.5v1511v16072017-03-17
CVE-2017-0023 [HIGH] CWE-119 CVE-2017-0023: The PDF library in Microsoft Edge; Windows 8.1; Windows Server 2012 and R2; Windows RT 8.1; and Wind The PDF library in Microsoft Edge; Windows 8.1; Windows Server 2012 and R2; Windows RT 8.1; and Windows 10, 1511, and 1607 allows remote attackers to execute arbitrary code via a crafted PDF file, aka "Microsoft PDF Remote Code Execution Vulnerability."
nvd
Microsoft Windows 10 vulnerabilities | cvebase