Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
216
Exploited in wild
26
Severity breakdown
CRITICAL68HIGH1907MEDIUM802LOW27

Vulnerabilities

Page 77 of 141
CVE-2020-0877HIGHCVSS 7.8v1607v1709+4 more2020-03-12
CVE-2020-0877 [HIGH] CVE-2020-0877: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0788, CVE-2020-0887.
nvd
CVE-2020-0814HIGHCVSS 7.8v1607v1709+4 more2020-03-12
CVE-2020-0814 [HIGH] CVE-2020-0814: An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Insta An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0779, CVE-2020-0798,
nvd
CVE-2020-0804HIGHCVSS 7.8v1607v1709+4 more2020-03-12
CVE-2020-0804 [HIGH] CVE-2020-0804: An elevation of privilege vulnerability exists in the way that the Windows Network Connections Servi An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0778, CVE-2020-0802, CVE-2020-0803, CVE-2020-0845.
nvd
CVE-2020-0776HIGHCVSS 7.8v1607v1709+4 more2020-03-12
CVE-2020-0776 [HIGH] CVE-2020-0776: An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly ha An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0858.
nvd
CVE-2020-0645HIGHCVSS 7.5v1607v1709+4 more2020-03-12
CVE-2020-0645 [HIGH] CVE-2020-0645: A tampering vulnerability exists when Microsoft IIS Server improperly handles malformed request head A tampering vulnerability exists when Microsoft IIS Server improperly handles malformed request headers, aka 'Microsoft IIS Server Tampering Vulnerability'.
nvd
CVE-2020-0798HIGHCVSS 7.8v1607v1709+4 more2020-03-12
CVE-2020-0798 [HIGH] CVE-2020-0798: An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer f An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE
nvd
CVE-2020-0797HIGHCVSS 7.8v1607v1709+4 more2020-03-12
CVE-2020-0797 [HIGH] CVE-2020-0797: An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handl An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0777, CVE-2020-0800, CVE-2020-0864, CVE-2020-0865, CVE-2020-0866, CVE-2020-0897.
nvd
CVE-2020-0763HIGHCVSS 7.8v1803v1809+2 more2020-03-12
CVE-2020-0763 [HIGH] CVE-2020-0763: An elevation of privilege vulnerability exists when Windows Defender Security Center handles certain An elevation of privilege vulnerability exists when Windows Defender Security Center handles certain objects in memory.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Windows Defender Security Center Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0762.
nvd
CVE-2020-0876HIGHCVSS 7.5v1903v19092020-03-12
CVE-2020-0876 [HIGH] CVE-2020-0876: An information disclosure vulnerability exists when the win32k component improperly provides kernel An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.
nvd
CVE-2020-0881HIGHCVSS 8.8v1607v1709+4 more2020-03-12
CVE-2020-0881 [HIGH] CVE-2020-0881: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0883.
nvd
CVE-2020-0860HIGHCVSS 7.8v1607v1709+4 more2020-03-12
CVE-2020-0860 [HIGH] CVE-2020-0860: An elevation of privilege vulnerability exists when the Windows ActiveX Installer Service improperly An elevation of privilege vulnerability exists when the Windows ActiveX Installer Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows ActiveX Installer Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0770, CVE-2020-0773.
nvd
CVE-2020-0793HIGHCVSS 7.8v1607v1709+4 more2020-03-12
CVE-2020-0793 [HIGH] CVE-2020-0793: An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service i An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0807HIGHCVSS 8.8v1803v1809+2 more2020-03-12
CVE-2020-0807 [HIGH] CVE-2020-0807: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0801, CVE-2020-0809, CVE-2020-0869.
nvd
CVE-2020-0762HIGHCVSS 7.8v1709v1803+3 more2020-03-12
CVE-2020-0762 [HIGH] CVE-2020-0762: An elevation of privilege vulnerability exists when Windows Defender Security Center handles certain An elevation of privilege vulnerability exists when Windows Defender Security Center handles certain objects in memory.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Windows Defender Security Center Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0763.
nvd
CVE-2020-0777HIGHCVSS 7.8v1607v1709+4 more2020-03-12
CVE-2020-0777 [HIGH] CVE-2020-0777: An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handl An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0797, CVE-2020-0800, CVE-2020-0864, CVE-2020-0865, CVE-2020-0866, CVE-2020-0897.
nvd
CVE-2020-0803HIGHCVSS 7.8v1607v1709+4 more2020-03-12
CVE-2020-0803 [HIGH] CVE-2020-0803: An elevation of privilege vulnerability exists in the way that the Windows Network Connections Servi An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0778, CVE-2020-0802, CVE-2020-0804, CVE-2020-0845.
nvd
CVE-2020-0785HIGHCVSS 7.1v1607v1709+4 more2020-03-12
CVE-2020-0785 [HIGH] CWE-269 CVE-2020-0785: An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) impro An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0773HIGHCVSS 7.8v1607v1709+4 more2020-03-12
CVE-2020-0773 [HIGH] CVE-2020-0773: An elevation of privilege vulnerability exists when the Windows ActiveX Installer Service improperly An elevation of privilege vulnerability exists when the Windows ActiveX Installer Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows ActiveX Installer Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0770, CVE-2020-0860.
nvd
CVE-2020-0791HIGHCVSS 7.8v1607v1709+4 more2020-03-12
CVE-2020-0791 [HIGH] CVE-2020-0791: An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handle An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0898.
nvd
CVE-2020-0854HIGHCVSS 7.1v1809v1903+1 more2020-03-12
CVE-2020-0854 [HIGH] CVE-2020-0854: An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnosti An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'.
nvd