Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27
Vulnerabilities
Page 66 of 141
CVE-2022-33670P3HIGHCVSS 7.8v20h2v21h1+2 more2022-08-09
CVE-2022-33670 [HIGH] CVE-2022-33670: Windows Partition Management Driver Elevation of Privilege Vulnerability
Windows Partition Management Driver Elevation of Privilege Vulnerability
nvd
CVE-2021-41346P3HIGHCVSS 7.8v20h2v21h1+1 more2021-10-13
CVE-2021-41346 [HIGH] CVE-2021-41346: Console Window Host Security Feature Bypass Vulnerability
Console Window Host Security Feature Bypass Vulnerability
nvd
CVE-2021-34456P3HIGHCVSS 7.8v20h2v21h1+4 more2021-07-16
CVE-2021-34456 [HIGH] CWE-269 CVE-2021-34456: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
nvd
CVE-2022-44689P3HIGHCVSS 7.8v20h2v21h1+3 more2022-12-13
CVE-2022-44689 [HIGH] CWE-269 CVE-2022-44689: Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability
Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-37984P3HIGHCVSS 7.8v20h2v21h1+3 more2022-10-11
CVE-2022-37984 [HIGH] CVE-2022-37984: Windows WLAN Service Elevation of Privilege Vulnerability
Windows WLAN Service Elevation of Privilege Vulnerability
nvd
CVE-2021-41377P3HIGHCVSS 7.8v20h2v21h1+4 more2021-11-10
CVE-2021-41377 [HIGH] CWE-269 CVE-2021-41377: Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2017-11927P3MEDIUMCVSS 6.5v1511v1607+2 more2017-12-12
CVE-2017-11927 [MEDIUM] CWE-200 CVE-2017-11927: Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R
Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow an information vulnerability due to the way the Windows its:// protocol handler determines the zone of a request, aka "Microsoft Windows Informat
nvd
CVE-2016-3369P3HIGHCVSS 7.5v15112016-09-14
CVE-2016-3369 [HIGH] CWE-119 CVE-2016-3369: Microsoft Windows 10 Gold and 1511 allows attackers to cause a denial of service via unspecified vec
Microsoft Windows 10 Gold and 1511 allows attackers to cause a denial of service via unspecified vectors, aka "Windows Denial of Service Vulnerability."
nvd
CVE-2019-1326P3HIGHCVSS 7.5v1607v1703+4 more2019-10-10
CVE-2019-1326 [HIGH] CVE-2019-1326: A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
nvd
CVE-2020-1028P3HIGHCVSS 7.8v1607v1709+4 more2020-05-21
CVE-2020-1028 [HIGH] CWE-787 CVE-2020-1028: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1126, CVE-2020-1136, CVE-2020-1150.
nvd
CVE-2020-1136P3HIGHCVSS 7.8v1607v1709+4 more2020-05-21
CVE-2020-1136 [HIGH] CVE-2020-1136: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1028, CVE-2020-1126, CVE-2020-1150.
nvd
CVE-2020-1307P3HIGHCVSS 7.8v1903v1909+1 more2020-06-09
CVE-2020-1307 [HIGH] CVE-2020-1307: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-127
nvd
CVE-2018-8424P3MEDIUMCVSS 6.5v1607v1703+2 more2018-09-13
CVE-2018-8424 [MEDIUM] CVE-2018-8424: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Wi
nvd
CVE-2020-1209P3HIGHCVSS 7.8v1903v1909+1 more2020-06-09
CVE-2020-1209 [HIGH] CVE-2020-1209: An elevation of privilege vulnerability exists in the way that the Windows Network List Service hand
An elevation of privilege vulnerability exists in the way that the Windows Network List Service handles objects in memory, aka 'Windows Network List Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1294P3HIGHCVSS 7.8v1607v1709+5 more2020-06-09
CVE-2020-1294 [HIGH] CVE-2020-1294: An elevation of privilege vulnerability exists in the way that the Windows WalletService handles obj
An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletService Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1287.
nvd
CVE-2020-1237P3HIGHCVSS 7.8v1709v1803+4 more2020-06-09
CVE-2020-1237 [HIGH] CVE-2020-1237: An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-1276, CVE-2020-1307, CVE
nvd
CVE-2020-1211P3HIGHCVSS 7.8v1607v1709+5 more2020-06-09
CVE-2020-1211 [HIGH] CVE-2020-1211: An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Servic
An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1314P3HIGHCVSS 7.8v1607v1709+5 more2020-06-09
CVE-2020-1314 [HIGH] CVE-2020-1314: An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF
An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server fails to properly handle messages sent from TSF clients, aka 'Windows Text Service Framework Elevation of Privilege Vulnerability'.
nvd
CVE-2021-1734P3HIGHCVSS 7.5v20h2v1607+4 more2021-02-25
CVE-2021-1734 [HIGH] CVE-2021-1734: Windows Remote Procedure Call Information Disclosure Vulnerability
Windows Remote Procedure Call Information Disclosure Vulnerability
nvd
CVE-2020-1534P3HIGHCVSS 7.8v1607v1709+5 more2020-08-17
CVE-2020-1534 [HIGH] CVE-2020-1534: An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles fi
An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability by correcting how
nvd