Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
226
Exploited in wild
51
Severity breakdown
CRITICAL68HIGH1906MEDIUM803LOW27
Vulnerabilities
Page 83 of 141
CVE-2017-0267P3MEDIUMCVSS 5.9v1511v1607+1 more2017-05-12
CVE-2017-0267 [MEDIUM] CWE-200 CVE-2017-0267: Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way
Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclo
nvd
CVE-2020-0754P3HIGHCVSS 7.8v1607v1709+3 more2020-02-11
CVE-2020-0754 [HIGH] CVE-2020-0754: An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0753.
nvd
CVE-2017-0050P3HIGHCVSS 7.8v1511v16072017-03-17
CVE-2017-0050 [HIGH] CVE-2017-0050: The kernel API in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7; Window
The kernel API in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7; Windows 8; Windows 10 Gold, 1511, and 1607; Windows RT 8.1; Windows Server 2012 Gold and R2; and Windows Server 2016 does not properly enforce permissions, which allows local users to spoof processes, spoof inter-process communication, or cause a denial of service via
nvd
CVE-2020-1191P3HIGHCVSS 7.8v1607v1709+4 more2020-05-21
CVE-2020-1191 [HIGH] CVE-2020-1191: An elevation of privilege vulnerability exists when the Windows State Repository Service improperly
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1124, CVE-2020-1131, CVE-2020-1134, CVE-2020-1144, CVE-2020-1184, CVE-2020-1185, CVE-2020-1186, CVE-2020-1187, CVE-2020-1188
nvd
CVE-2016-3349P3HIGHCVSS 7.8v15112016-09-14
CVE-2016-3349 [HIGH] CWE-264 CVE-2016-3349: The kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, a
The kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
nvd
CVE-2018-8562P3HIGHCVSS 7.8v1607v1703+18 more2018-11-14
CVE-2018-8562 [HIGH] CWE-404 CVE-2018-8562: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server
nvd
CVE-2019-1423P3HIGHCVSS 7.8v19032019-11-12
CVE-2019-1423 [HIGH] CVE-2019-1423: An elevation of privilege vulnerability exists in the way that the StartTileData.dll handles file cr
An elevation of privilege vulnerability exists in the way that the StartTileData.dll handles file creation in protected locations, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1420, CVE-2019-1422.
nvd
CVE-2019-1393P3HIGHCVSS 7.8v1607v1709+3 more2019-11-12
CVE-2019-1393 [HIGH] CWE-787 CVE-2019-1393: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1394, CVE-2019-1395, CVE-2019-1396, CVE-2019-1408, CVE-2019-1434.
nvd
CVE-2019-1408P3HIGHCVSS 7.8v1607v1709+3 more2019-11-12
CVE-2019-1408 [HIGH] CVE-2019-1408: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1393, CVE-2019-1394, CVE-2019-1395, CVE-2019-1396, CVE-2019-1434.
nvd
CVE-2018-8233P3HIGHCVSS 7.8v1803vVersion 1803 for 32-bit Systems+1 more2018-06-14
CVE-2018-8233 [HIGH] CWE-404 CVE-2018-8233: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 10, Windows 10 Servers.
nvd
CVE-2017-8622P3HIGHCVSS 7.8v17032017-08-08
CVE-2017-8622 [HIGH] CVE-2017-8622: Windows Subsystem for Linux in Windows 10 1703 allows an elevation of privilege vulnerability when i
Windows Subsystem for Linux in Windows 10 1703 allows an elevation of privilege vulnerability when it fails to properly handle handles NT pipes, aka "Windows Subsystem for Linux Elevation of Privilege Vulnerability".
nvd
CVE-2017-8624P3HIGHCVSS 7.8v1511v1607+1 more2017-08-08
CVE-2017-8624 [HIGH] CVE-2017-8624: CLFS in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and
CLFS in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way it handles objects in memory, aka "Windows CLFS Elevation of Privilege Vulnerability".
nvd
CVE-2016-3286P3HIGHCVSS 7.3v15112016-07-13
CVE-2016-3286 [HIGH] CVE-2016-3286: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3249, CVE-2
nvd
CVE-2016-3249P3HIGHCVSS 7.3v15112016-07-13
CVE-2016-3249 [HIGH] CWE-264 CVE-2016-3249: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-325
nvd
CVE-2018-1009P3HIGHCVSS 7.8v1511v1607+12 more2018-04-12
CVE-2018-1009 [HIGH] CVE-2018-1009: An elevation of privilege vulnerability exists when Windows improperly handles objects in memory and
An elevation of privilege vulnerability exists when Windows improperly handles objects in memory and incorrectly maps kernel memory, aka "Microsoft DirectX Graphics Kernel Subsystem Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
nvd
CVE-2016-7222P3HIGHCVSS 7.8v1511v16072016-11-10
CVE-2016-7222 [HIGH] CWE-254 CVE-2016-7222: Task Scheduler in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows local use
Task Scheduler in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows local users to gain privileges via a crafted UNC pathname in a task, aka "Task Scheduler Elevation of Privilege Vulnerability."
nvd
CVE-2020-0669P3HIGHCVSS 7.8v1803v1809+2 more2020-02-11
CVE-2020-0669 [HIGH] CVE-2020-0669: An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0668, CVE-2020-0670, CVE-2020-0671, CVE-2020-0672.
nvd
CVE-2017-8468P3HIGHCVSS 7.8v1511v1607+1 more2017-06-15
CVE-2017-8468 [HIGH] CVE-2017-8468: Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1
Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to run processes in an elevated context when the Windows kernel improperly handles objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-8465.
nvd
CVE-2020-0814P3HIGHCVSS 7.8v1607v1709+4 more2020-03-12
CVE-2020-0814 [HIGH] CVE-2020-0814: An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Insta
An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0779, CVE-2020-0798,
nvd
CVE-2018-8485P3HIGHCVSS 7.8v1607v1703+18 more2018-11-14
CVE-2018-8485 [HIGH] CWE-404 CVE-2018-8485: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, ak
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8554, CV
nvd