Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27
Vulnerabilities
Page 58 of 141
CVE-2018-0966P4LOWCVSS 3.3PoCv1511v1607+12 more2018-04-12
CVE-2018-0966 [LOW] CWE-367 CVE-2018-0966: A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Dev
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2019-1422P3HIGHCVSS 7.8v1607v1709+3 more2019-11-12
CVE-2019-1422 [HIGH] CVE-2019-1422: An elevation of privilege vulnerability exists in the way that the iphlpsvc.dll handles file creatio
An elevation of privilege vulnerability exists in the way that the iphlpsvc.dll handles file creation allowing for a file overwrite, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1420, CVE-2019-1423.
nvd
CVE-2018-8400P3HIGHCVSS 7.8v1709v1803+10 more2018-08-15
CVE-2018-8400 [HIGH] CWE-404 CVE-2018-8400: An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver imp
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID is unique from CVE-2018-8401, CVE-2018-8405, CVE-2018-8406.
nvd
CVE-2018-8401P3HIGHCVSS 7.8v1607v1703+2 more2018-08-15
CVE-2018-8401 [HIGH] CVE-2018-8401: An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver imp
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8400, CVE-2018-8405, CVE-2018-8406.
nvd
CVE-2019-0685P3HIGHCVSS 7.8v1607v1703+3 more2019-04-09
CVE-2019-0685 [HIGH] CVE-2019-0685: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0803, CVE-2019-0859.
nvd
CVE-2017-8720P3HIGHCVSS 7.8v1511v1607+1 more2017-09-13
CVE-2017-8720 [HIGH] CVE-2017-8720: The Microsoft Windows graphics component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7
The Microsoft Windows graphics component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when the Win32k component fails to properly handle objects in memory, aka "Win32k Eleva
nvd
CVE-2016-7260P3HIGHCVSS 7.8v1511v16072016-12-20
CVE-2016-7260 [HIGH] CWE-264 CVE-2016-7260: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
nvd
CVE-2018-8164P3HIGHCVSS 7.8v1607v1703+2 more2018-05-09
CVE-2018-8164 [HIGH] CVE-2018-8164: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows
nvd
CVE-2016-3305P3HIGHCVSS 7.8v1511v1607+1 more2016-09-14
CVE-2016-3305 [HIGH] CWE-19 CVE-2016-3305: The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 mishandles session objects, which allows local users to hijack sessions, and consequently gain privileges, via a crafted application, aka "Windows Session Object El
nvd
CVE-2022-21901P3HIGHCVSS 8.0v20h2v21h1+4 more2022-01-11
CVE-2022-21901 [HIGH] CVE-2022-21901: Windows Hyper-V Elevation of Privilege Vulnerability
Windows Hyper-V Elevation of Privilege Vulnerability
nvd
CVE-2020-16920P3HIGHCVSS 7.8v1607v1709+5 more2020-10-16
CVE-2020-16920 [HIGH] CVE-2020-16920: <p>An elevation of privilege vulnerability exists when the Windows Application Compatibility Client
An elevation of privilege vulnerability exists when the Windows Application Compatibility Client Library improperly handles registry operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.
To exploit the vulnerability, an attacker would first need code execution on a victim system. An attacker could then run a spec
nvd
CVE-2017-0056P3HIGHCVSS 7.8v1511v16072017-03-17
CVE-2017-0056 [HIGH] CVE-2017-0056: The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows
The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is d
nvd
CVE-2022-30166P3HIGHCVSS 7.8v20h2v21h1+3 more2022-06-15
CVE-2022-30166 [HIGH] CVE-2022-30166: Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
nvd
CVE-2020-1574P3HIGHCVSS 7.3v1909v20042020-08-17
CVE-2020-1574 [HIGH] CWE-119 CVE-2020-1574: A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handle
A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code.
Exploitation of the vulnerability requires that a program process a specially crafted image file.
The update addresses the vulnerability by correct
nvd
CVE-2021-26871P3HIGHCVSS 7.8v20h2v1607+4 more2021-03-11
CVE-2021-26871 [HIGH] CVE-2021-26871: Windows WalletService Elevation of Privilege Vulnerability
Windows WalletService Elevation of Privilege Vulnerability
nvd
CVE-2020-1070P3HIGHCVSS 7.8v1607v1709+4 more2020-05-21
CVE-2020-1070 [HIGH] CVE-2020-1070: An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly all
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Print Spooler Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1048.
nvd
CVE-2021-1648P3HIGHCVSS 7.8v20h2v1607+4 more2021-01-12
CVE-2021-1648 [HIGH] CWE-269 CVE-2021-1648: Microsoft splwow64 Elevation of Privilege Vulnerability
Microsoft splwow64 Elevation of Privilege Vulnerability
nvd
CVE-2023-36906P3HIGHCVSS 7.5fixed in 10.0.10240.201072023-08-08
CVE-2023-36906 [HIGH] CWE-170 CVE-2023-36906: Windows Cryptographic Services Information Disclosure Vulnerability
Windows Cryptographic Services Information Disclosure Vulnerability
nvd
CVE-2021-42279P3HIGHCVSS 7.5v20h2v21h1+4 more2021-11-10
CVE-2021-42279 [HIGH] CWE-787 CVE-2021-42279: Chakra Scripting Engine Memory Corruption Vulnerability
Chakra Scripting Engine Memory Corruption Vulnerability
nvd
CVE-2021-26862P3HIGHCVSS 7.8v20h2v1607+4 more2021-03-11
CVE-2021-26862 [HIGH] CWE-59 CVE-2021-26862: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
nvd