Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27
Vulnerabilities
Page 31 of 141
CVE-2017-8470P4MEDIUMCVSS 5.0PoCv1511v1607+1 more2017-06-15
CVE-2017-8470 [MEDIUM] CWE-200 CVE-2017-8470: Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an authenticated attacker to run a specially crafted application when the Windows kernel improperly initializes objects in memory, aka "Win32k Information Disclosu
nvd
CVE-2022-30139P3HIGHCVSS 7.5v20h2v21h1+3 more2022-06-15
CVE-2022-30139 [HIGH] CVE-2022-30139: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2019-1337P4MEDIUMCVSS 5.5PoCv1809v19032019-10-10
CVE-2019-1337 [MEDIUM] CWE-200 CVE-2019-1337: An information disclosure vulnerability exists when Windows Update Client fails to properly handle o
An information disclosure vulnerability exists when Windows Update Client fails to properly handle objects in memory, aka 'Windows Update Client Information Disclosure Vulnerability'.
nvd
CVE-2017-0166P3HIGHCVSS 8.1v1511v1607+1 more2017-04-12
CVE-2017-0166 [HIGH] CWE-131 CVE-2017-0166: An elevation of privilege vulnerability exists in Windows when LDAP request buffer lengths are impro
An elevation of privilege vulnerability exists in Windows when LDAP request buffer lengths are improperly calculated. In a remote attack scenario, an attacker could exploit this vulnerability by running a specially crafted application to send malicious traffic to a Domain Controller, aka "LDAP Elevation of Privilege Vulnerability."
nvd
CVE-2016-3312P3CRITICALCVSS 9.1v15112016-08-09
CVE-2016-3312 [CRITICAL] CWE-200 CVE-2016-3312: ActiveSyncProvider in Microsoft Windows 10 Gold and 1511 allows attackers to discover credentials by
ActiveSyncProvider in Microsoft Windows 10 Gold and 1511 allows attackers to discover credentials by leveraging failure of Universal Outlook to obtain a secure connection, aka "Universal Outlook Information Disclosure Vulnerability."
nvd
CVE-2017-11831P4MEDIUMCVSS 4.7PoCv1511v1607+2 more2017-11-15
CVE-2017-11831 [MEDIUM] CWE-200 CVE-2017-11831: Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows
Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log on to an affected system, and run a specially crafted application that can compromise the user's system due t
nvd
CVE-2017-8699P3HIGHCVSS 7.0v1511v1607+1 more2017-09-13
CVE-2017-8699 [HIGH] CWE-20 CVE-2017-8699: Windows Shell in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT
Windows Shell in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to run arbitrary code in the context of the current user, due to the way that Windows Shell validates file copy destinations, aka "Windows Shell
nvd
CVE-2021-26863P3HIGHCVSS 7.8v20h2v1803+3 more2021-03-11
CVE-2021-26863 [HIGH] CWE-269 CVE-2021-26863: Windows Win32k Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
nvd
CVE-2022-29104P3HIGHCVSS 7.8v20h2v21h1+4 more2022-05-10
CVE-2022-29104 [HIGH] CVE-2022-29104: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2019-1359P3HIGHCVSS 7.8v1607v1703+4 more2019-10-10
CVE-2019-1359 [HIGH] CVE-2019-1359: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1358.
nvd
CVE-2021-43883P3HIGHCVSS 7.8v20h2v21h1+5 more2021-12-15
CVE-2021-43883 [HIGH] CVE-2021-43883: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2020-1255P3HIGHCVSS 8.8v1607v1709+5 more2020-06-09
CVE-2020-1255 [HIGH] CVE-2020-1255: An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Serv
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
nvd
CVE-2021-43893P3HIGHCVSS 7.5v20h2v21h1+5 more2021-12-15
CVE-2021-43893 [HIGH] CWE-668 CVE-2021-43893: Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability
Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability
nvd
CVE-2020-1410P3HIGHCVSS 7.8v1607v1709+5 more2020-07-14
CVE-2020-1410 [HIGH] CVE-2020-1410: A remote code execution vulnerability exists when Windows Address Book (WAB) improperly processes vc
A remote code execution vulnerability exists when Windows Address Book (WAB) improperly processes vcard files.To exploit the vulnerability, an attacker could send a malicious vcard that a victim opens using Windows Address Book (WAB), aka 'Windows Address Book Remote Code Execution Vulnerability'.
nvd
CVE-2019-1159P3HIGHCVSS 7.8v1607v1703+4 more2019-08-14
CVE-2019-1159 [HIGH] CVE-2019-1159: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, a
nvd
CVE-2020-0995P3HIGHCVSS 7.8v1607v1709+4 more2020-04-15
CVE-2020-0995 [HIGH] CVE-2020-0995: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0889, CVE-2020-0953, CVE-2020-0959, CVE-2020-0960, CVE-2020-0988, CVE-2020-0992, CVE-2020-0994, CVE-2020-0999, CVE-2020-1008.
nvd
CVE-2019-1241P3HIGHCVSS 7.8v1607v1703+4 more2019-09-11
CVE-2019-1241 [HIGH] CVE-2019-1241: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1240, CVE-2019-1242, CVE-2019-1243, CVE-2019-1246, CVE-2019-1247, CVE-2019-1248, CVE-2019-1249, CVE-2019-1250.
nvd
CVE-2020-16933P3HIGHCVSS 8.8v1607v1709+5 more2020-10-16
CVE-2020-16933 [HIGH] CVE-2020-16933: <p>A security feature bypass vulnerability exists in Microsoft Word software when it fails to proper
A security feature bypass vulnerability exists in Microsoft Word software when it fails to properly handle .LNK files. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the
nvd
CVE-2020-17162P3HIGHCVSS 8.8v1607v1803+4 more2021-02-25
CVE-2020-17162 [HIGH] CVE-2020-17162: Microsoft Windows Security Feature Bypass Vulnerability
Microsoft Windows Security Feature Bypass Vulnerability
nvd
CVE-2016-0150P3HIGHCVSS 7.5v15112016-04-12
CVE-2016-0150 [HIGH] CWE-19 CVE-2016-0150: HTTP.sys in Microsoft Windows 10 Gold and 1511 allows remote attackers to cause a denial of service
HTTP.sys in Microsoft Windows 10 Gold and 1511 allows remote attackers to cause a denial of service (system hang) via crafted HTTP 2.0 requests, aka "HTTP.sys Denial of Service Vulnerability."
nvd