Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27
Vulnerabilities
Page 57 of 141
CVE-2020-1531P3HIGHCVSS 7.8v1607v1709+5 more2020-08-17
CVE-2020-1531 [HIGH] CVE-2020-1531: An elevation of privilege vulnerability exists when the Windows Accounts Control improperly handles
An elevation of privilege vulnerability exists when the Windows Accounts Control improperly handles memory.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability by correcting how the Wind
nvd
CVE-2017-0163P3HIGHCVSS 7.6v1511v1607+1 more2017-04-12
CVE-2017-0163 [HIGH] CVE-2017-0163: A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host s
A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is unique from CVE-2017-0162, CVE-2017-0180, and CVE-2017-0181.
nvd
CVE-2017-0181P3HIGHCVSS 7.6v1511v1607+1 more2017-04-12
CVE-2017-0181 [HIGH] CVE-2017-0181: A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Window
A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Windows 10 or Windows Server 2016 host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is unique from CVE-2017-0162, CVE-2017-0163, and CVE-2017-0180.
nvd
CVE-2020-17055P3HIGHCVSS 7.8v20h2v1607+6 more2020-11-11
CVE-2020-17055 [HIGH] CVE-2020-17055: Windows Remote Access Elevation of Privilege Vulnerability
Windows Remote Access Elevation of Privilege Vulnerability
nvd
CVE-2020-17044P3HIGHCVSS 7.8v20h2v1607+6 more2020-11-11
CVE-2020-17044 [HIGH] CVE-2020-17044: Windows Remote Access Elevation of Privilege Vulnerability
Windows Remote Access Elevation of Privilege Vulnerability
nvd
CVE-2020-17043P3HIGHCVSS 7.8v20h2v1607+5 more2020-11-11
CVE-2020-17043 [HIGH] CVE-2020-17043: Windows Remote Access Elevation of Privilege Vulnerability
Windows Remote Access Elevation of Privilege Vulnerability
nvd
CVE-2021-28319P3HIGHCVSS 7.5v20h2v1803+3 more2021-04-13
CVE-2021-28319 [HIGH] CVE-2021-28319: Windows TCP/IP Driver Denial of Service Vulnerability
Windows TCP/IP Driver Denial of Service Vulnerability
nvd
CVE-2022-37985P4MEDIUMCVSS 5.5v20h2v21h1+3 more2022-10-11
CVE-2022-37985 [MEDIUM] CVE-2022-37985: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2016-3252P3HIGHCVSS 7.3v15112016-07-13
CVE-2016-3252 [HIGH] CVE-2016-3252: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3249, CVE-2
nvd
CVE-2021-26433P3HIGHCVSS 7.5v20h2v21h1+4 more2021-08-12
CVE-2021-26433 [HIGH] CVE-2021-26433: Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
nvd
CVE-2021-36926P3HIGHCVSS 7.5v20h2v21h1+4 more2021-08-12
CVE-2021-36926 [HIGH] CVE-2021-36926: Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
nvd
CVE-2021-36933P3HIGHCVSS 7.5v20h2v21h1+4 more2021-08-12
CVE-2021-36933 [HIGH] CVE-2021-36933: Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
nvd
CVE-2021-36932P3HIGHCVSS 7.5v20h2v21h1+4 more2021-08-12
CVE-2021-36932 [HIGH] CVE-2021-36932: Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
nvd
CVE-2020-1362P3HIGHCVSS 7.8v1607v1709+5 more2020-07-14
CVE-2020-1362 [HIGH] CVE-2020-1362: An elevation of privilege vulnerability exists in the way that the Windows WalletService handles obj
An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletService Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1344, CVE-2020-1369.
nvd
CVE-2016-0014P3HIGHCVSS 7.8v15112016-01-13
CVE-2016-0014 [HIGH] CWE-426 CVE-2016-0014: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "DLL Loading Elevation of Privilege Vulnerability."
nvd
CVE-2017-8465P3HIGHCVSS 7.8v1511v1607+1 more2017-06-15
CVE-2017-8465 [HIGH] CWE-281 CVE-2017-8465: Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1
Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to run processes in an elevated context when the Windows kernel improperly handles objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-8468.
nvd
CVE-2020-0753P3HIGHCVSS 7.8v1607v1709+3 more2020-02-11
CVE-2020-0753 [HIGH] CVE-2020-0753: An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0754.
nvd
CVE-2020-0887P3HIGHCVSS 7.8v1607v1709+4 more2020-03-12
CVE-2020-0887 [HIGH] CVE-2020-0887: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0788, CVE-2020-0877.
nvd
CVE-2020-16949P3HIGHCVSS 7.5v1607v1709+5 more2020-10-16
CVE-2020-16949 [HIGH] CWE-401 CVE-2020-16949: <p>A denial of service vulnerability exists in Microsoft Outlook software when the software fails to
A denial of service vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could cause a remote denial of service against a system.
Exploitation of the vulnerability requires that a specially crafted email be sent to a vulnerable Outlook
nvd
CVE-2016-0048P3HIGHCVSS 7.8v15112016-02-10
CVE-2016-0048 [HIGH] CWE-264 CVE-2016-0048: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
nvd