Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27
Vulnerabilities
Page 29 of 141
CVE-2019-1344P4MEDIUMCVSS 5.5PoCv1607v1703+4 more2019-10-10
CVE-2019-1344 [MEDIUM] CWE-125 CVE-2019-1344: An information disclosure vulnerability exists in the way that the Windows Code Integrity Module han
An information disclosure vulnerability exists in the way that the Windows Code Integrity Module handles objects in memory, aka 'Windows Code Integrity Module Information Disclosure Vulnerability'.
nvd
CVE-2019-1153P4MEDIUMCVSS 5.5PoCv1607v1703+4 more2019-08-14
CVE-2019-1153 [MEDIUM] CWE-125 CVE-2019-1153: An information disclosure vulnerability exists when the Microsoft Windows Graphics Component imprope
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a spe
nvd
CVE-2019-1148P4MEDIUMCVSS 5.5PoCv1607v1703+4 more2019-08-14
CVE-2019-1148 [MEDIUM] CWE-125 CVE-2019-1148: An information disclosure vulnerability exists when the Microsoft Windows Graphics Component imprope
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a spe
nvd
CVE-2017-8563P3HIGHCVSS 8.1v1511v1607+1 more2017-07-11
CVE-2017-8563 [HIGH] CWE-281 CVE-2017-8563: Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Kerberos falling back to NT LAN Manager (NTLM) Authentication Protocol as the default authentication protocol, aka "Windo
nvd
CVE-2018-8432P3HIGHCVSS 7.8v1809vVersion 1809 for 32-bit Systems+1 more2018-10-10
CVE-2018-8432 [HIGH] CVE-2018-8432: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Remote Code Execution Vulnerability." This affects Windows 7, Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Microsoft Excel Viewer, Microsoft PowerPoint Viewer, Windows Server 2019, Windows
nvd
CVE-2019-0617P3HIGHCVSS 7.8v1607v1703+3 more2019-04-08
CVE-2019-0617 [HIGH] CVE-2019-0617: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.
nvd
CVE-2020-1013P3HIGHCVSS 8.1v1607v1709+5 more2020-09-11
CVE-2020-1013 [HIGH] CVE-2020-1013: <p>An elevation of privilege vulnerability exists when Microsoft Windows processes group policy upda
An elevation of privilege vulnerability exists when Microsoft Windows processes group policy updates. An attacker who successfully exploited this vulnerability could potentially escalate permissions or perform additional privileged actions on the target machine.
To exploit this vulnerability, an attacker would need to launch a man-in-the-middle (MiTM) attack ag
nvd
CVE-2019-0595P3HIGHCVSS 7.8v1607v1703+3 more2019-03-05
CVE-2019-0595 [HIGH] CVE-2019-0595: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0596, CVE-2019-0597, CVE-2019-0598, CVE-2019-0599, CVE-2019-0625.
nvd
CVE-2022-22715P3HIGHCVSS 7.8v20h2v21h1+3 more2022-02-09
CVE-2022-22715 [HIGH] CWE-191 CVE-2022-22715: Named Pipe File System Elevation of Privilege Vulnerability
Named Pipe File System Elevation of Privilege Vulnerability
nvd
CVE-2019-1243P3HIGHCVSS 7.8v1607v1703+4 more2019-09-11
CVE-2019-1243 [HIGH] CVE-2019-1243: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1240, CVE-2019-1241, CVE-2019-1242, CVE-2019-1246, CVE-2019-1247, CVE-2019-1248, CVE-2019-1249, CVE-2019-1250.
nvd
CVE-2019-1250P3HIGHCVSS 7.8v1607v1703+4 more2019-09-11
CVE-2019-1250 [HIGH] CVE-2019-1250: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1240, CVE-2019-1241, CVE-2019-1242, CVE-2019-1243, CVE-2019-1246, CVE-2019-1247, CVE-2019-1248, CVE-2019-1249.
nvd
CVE-2017-8664P3HIGHCVSS 8.8v1511v1607+1 more2017-08-08
CVE-2017-8664 [HIGH] CWE-20 CVE-2017-8664: Windows Hyper-V in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 15
Windows Hyper-V in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability".
nvd
CVE-2020-1129P3HIGHCVSS 8.8v1607v1709+5 more2020-09-11
CVE-2020-1129 [HIGH] CVE-2020-1129: <p>A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library han
A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
Exploitation of the vuln
nvd
CVE-2022-24533P3HIGHCVSS 8.0v20h2v21h1+4 more2022-04-15
CVE-2022-24533 [HIGH] CVE-2022-24533: Remote Desktop Protocol Remote Code Execution Vulnerability
Remote Desktop Protocol Remote Code Execution Vulnerability
nvd
CVE-2019-0576P3HIGHCVSS 7.8v1607v1703+3 more2019-01-08
CVE-2019-0576 [HIGH] CVE-2019-0576: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008
nvd
CVE-2019-0580P3HIGHCVSS 7.8v1607v1703+3 more2019-01-08
CVE-2019-0580 [HIGH] CVE-2019-0580: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008
nvd
CVE-2019-0579P3HIGHCVSS 7.8v1607v1703+3 more2019-01-08
CVE-2019-0579 [HIGH] CVE-2019-0579: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008
nvd
CVE-2019-0577P3HIGHCVSS 7.8v1607v1703+3 more2019-01-08
CVE-2019-0577 [HIGH] CVE-2019-0577: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008
nvd
CVE-2022-21920P3HIGHCVSS 8.8v20h2v21h1+4 more2022-01-11
CVE-2022-21920 [HIGH] CVE-2022-21920: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2017-0021P3CRITICALCVSS 9.0v16072017-03-17
CVE-2017-0021 [CRITICAL] CVE-2017-0021: Hyper-V in Microsoft Windows 10 1607 and Windows Server 2016 does not properly validate vSMB packet
Hyper-V in Microsoft Windows 10 1607 and Windows Server 2016 does not properly validate vSMB packet data, which allows attackers to execute arbitrary code on a target OS, aka "Hyper-V System Data Structure Vulnerability." This vulnerability is different from that described in CVE-2017-0095.
nvd