Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27
Vulnerabilities
Page 62 of 141
CVE-2020-1590P3HIGHCVSS 7.8v1809v1903+2 more2020-09-11
CVE-2020-1590 [HIGH] CVE-2020-1590: <p>An elevation of privilege vulnerability exists when the Connected User Experiences and Telemetry
An elevation of privilege vulnerability exists when the Connected User Experiences and Telemetry Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges on the victim system.
To exploit the vulnerability, an attacker would first have to gain execution on the victim system, then run a sp
nvd
CVE-2019-1232P3HIGHCVSS 7.8v1607v1703+4 more2019-09-11
CVE-2019-1232 [HIGH] CVE-2019-1232: An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service i
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operations, aka 'Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability'.
nvd
CVE-2021-38634P3HIGHCVSS 7.8v20h2v21h1+4 more2021-09-15
CVE-2021-38634 [HIGH] CWE-269 CVE-2021-38634: Microsoft Windows Update Client Elevation of Privilege Vulnerability
Microsoft Windows Update Client Elevation of Privilege Vulnerability
nvd
CVE-2020-1254P3HIGHCVSS 7.8v1607v1709+5 more2020-06-09
CVE-2020-1254 [HIGH] CVE-2020-1254: An elevation of privilege vulnerability exists when Windows Modules Installer Service improperly han
An elevation of privilege vulnerability exists when Windows Modules Installer Service improperly handles class object members.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows Modules Installer Service Elevation of Privilege Vulnerability'.
nvd
CVE-2021-40489P3HIGHCVSS 7.8v20h2v21h1+4 more2021-10-13
CVE-2021-40489 [HIGH] CWE-269 CVE-2021-40489: Storage Spaces Controller Elevation of Privilege Vulnerability
Storage Spaces Controller Elevation of Privilege Vulnerability
nvd
CVE-2021-40478P3HIGHCVSS 7.8v20h2v21h1+4 more2021-10-13
CVE-2021-40478 [HIGH] CWE-269 CVE-2021-40478: Storage Spaces Controller Elevation of Privilege Vulnerability
Storage Spaces Controller Elevation of Privilege Vulnerability
nvd
CVE-2021-31952P3HIGHCVSS 7.8v20h2v21h1+2 more2021-06-08
CVE-2021-31952 [HIGH] CVE-2021-31952: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
nvd
CVE-2021-41345P3HIGHCVSS 7.8v20h2v21h1+4 more2021-10-13
CVE-2021-41345 [HIGH] CWE-269 CVE-2021-41345: Storage Spaces Controller Elevation of Privilege Vulnerability
Storage Spaces Controller Elevation of Privilege Vulnerability
nvd
CVE-2022-41052P3HIGHCVSS 7.8v20h2v21h1+4 more2022-11-09
CVE-2022-41052 [HIGH] CVE-2022-41052: Windows Graphics Component Remote Code Execution Vulnerability
Windows Graphics Component Remote Code Execution Vulnerability
nvd
CVE-2021-27090P3HIGHCVSS 7.8v20h2v20042021-04-13
CVE-2021-27090 [HIGH] CVE-2021-27090: Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
nvd
CVE-2020-1538P3HIGHCVSS 7.8v1607v1709+5 more2020-08-17
CVE-2020-1538 [HIGH] CVE-2020-1538: An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles
An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles memory.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability by correcting how the Wind
nvd
CVE-2020-1517P3HIGHCVSS 7.8v1607v1803+4 more2020-08-17
CVE-2020-1517 [HIGH] CVE-2020-1517: An elevation of privilege vulnerability exists when the Windows File Server Resource Management Serv
An elevation of privilege vulnerability exists when the Windows File Server Resource Management Service improperly handles memory.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability by
nvd
CVE-2020-1526P3HIGHCVSS 7.8v1607v1709+5 more2020-08-17
CVE-2020-1526 [HIGH] CVE-2020-1526: An elevation of privilege vulnerability exists when the Windows Network Connection Broker improperly
An elevation of privilege vulnerability exists when the Windows Network Connection Broker improperly handles memory.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability by correcting ho
nvd
CVE-2020-1488P3HIGHCVSS 7.8v1607v1709+5 more2020-08-17
CVE-2020-1488 [HIGH] CWE-269 CVE-2020-1488: An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperl
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.
To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.
The security update addresses the vulnerability by corr
nvd
CVE-2020-1430P3HIGHCVSS 7.8v1607v1709+5 more2020-07-14
CVE-2020-1430 [HIGH] CVE-2020-1430: An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles
An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows UPnP Device Host Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1354.
nvd
CVE-2020-1354P3HIGHCVSS 7.8v1607v1709+5 more2020-07-14
CVE-2020-1354 [HIGH] CVE-2020-1354: An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles
An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows UPnP Device Host Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1430.
nvd
CVE-2020-1271P3HIGHCVSS 7.8v1607v1709+4 more2020-06-09
CVE-2020-1271 [HIGH] CVE-2020-1271: An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles fi
An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0912P3HIGHCVSS 7.8v1607v1709+5 more2020-09-11
CVE-2020-0912 [HIGH] CVE-2020-0912: <p>An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider
An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability by correct
nvd
CVE-2023-21817P3HIGHCVSS 7.8fixed in 10.0.10240.197472023-02-14
CVE-2023-21817 [HIGH] CWE-287 CVE-2023-21817: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2022-35771P3HIGHCVSS 7.8v20h2v21h1+3 more2022-08-09
CVE-2022-35771 [HIGH] CWE-269 CVE-2022-35771: Windows Defender Credential Guard Elevation of Privilege Vulnerability
Windows Defender Credential Guard Elevation of Privilege Vulnerability
nvd