Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
216
Exploited in wild
26
Severity breakdown
CRITICAL68HIGH1907MEDIUM802LOW27

Vulnerabilities

Page 84 of 141
CVE-2020-0675MEDIUMCVSS 5.5v1607v1709+4 more2020-02-11
CVE-2020-0675 [MEDIUM] CVE-2020-0675: An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service whe An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to properly handle objects in memory.To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.The security update addresses the vulnerability by correcting how the service handles o
nvd
CVE-2020-0676MEDIUMCVSS 5.5v1607v1709+4 more2020-02-11
CVE-2020-0676 [MEDIUM] CVE-2020-0676: An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service whe An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to properly handle objects in memory.To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.The security update addresses the vulnerability by correcting how the service handles o
nvd
CVE-2020-0689MEDIUMCVSS 6.7v1607v1709+4 more2020-02-11
CVE-2020-0689 [MEDIUM] CVE-2020-0689: A security feature bypass vulnerability exists in secure boot, aka 'Microsoft Secure Boot Security F A security feature bypass vulnerability exists in secure boot, aka 'Microsoft Secure Boot Security Feature Bypass Vulnerability'.
nvd
CVE-2020-0661MEDIUMCVSS 6.8v1607v1809+1 more2020-02-11
CVE-2020-0661 [MEDIUM] CWE-20 CVE-2020-0661: A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly v A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-0751.
nvd
CVE-2020-0756MEDIUMCVSS 5.5v1607v1709+4 more2020-02-11
CVE-2020-0756 [MEDIUM] CVE-2020-0756: An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service whe An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to properly handle objects in memory.To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.The security update addresses the vulnerability by correcting how the service handles o
nvd
CVE-2020-0705MEDIUMCVSS 5.5v1607v1709+2 more2020-02-11
CVE-2020-0705 [MEDIUM] CVE-2020-0705: An information disclosure vulnerability exists when the Windows Network Driver Interface Specificati An information disclosure vulnerability exists when the Windows Network Driver Interface Specification (NDIS) improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Network Driver Interface Specification (NDIS) Information Disclosure Vulnerability'.
nvd
CVE-2020-0751MEDIUMCVSS 6.0v1903v19092020-02-11
CVE-2020-0751 [MEDIUM] CVE-2020-0751: A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly v A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system.To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application.The secur
nvd
CVE-2019-1454MEDIUMCVSS 5.5v1607v1703+4 more2020-01-24
CVE-2019-1454 [MEDIUM] CWE-269 CVE-2019-1454: An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) impro An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.
nvd
CVE-2019-9510HIGHCVSS 7.8v18032020-01-15
CVE-2019-9510 [HIGH] CWE-288 CVE-2019-9510: A vulnerability in Microsoft Windows 10 1803 and Windows Server 2019 and later systems can allow aut A vulnerability in Microsoft Windows 10 1803 and Windows Server 2019 and later systems can allow authenticated RDP-connected clients to gain access to user sessions without needing to interact with the Windows lock screen. Should a network anomaly trigger a temporary RDP disconnect, Automatic Reconnection of the RDP session will be restored to an unlock
nvd
CVE-2020-0632HIGHCVSS 7.8v1607v1709+4 more2020-01-14
CVE-2020-0632 [HIGH] CVE-2020-0632: An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles ob An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CV
nvd
CVE-2020-0630HIGHCVSS 7.8v1607v1709+4 more2020-01-14
CVE-2020-0630 [HIGH] CVE-2020-0630: An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles ob An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0631, CVE-2020-0632, CV
nvd
CVE-2020-0626HIGHCVSS 7.8v1607v1709+4 more2020-01-14
CVE-2020-0626 [HIGH] CVE-2020-0626: An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles ob An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CV
nvd
CVE-2020-0625HIGHCVSS 7.8v1607v1709+4 more2020-01-14
CVE-2020-0625 [HIGH] CVE-2020-0625: An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles ob An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CV
nvd
CVE-2020-0611HIGHCVSS 7.5v1607v1709+4 more2020-01-14
CVE-2020-0611 [HIGH] CVE-2020-0611: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.
nvd
CVE-2020-0642HIGHCVSS 7.8PoCv1607v1709+4 more2020-01-14
CVE-2020-0642 [HIGH] CVE-2020-0642: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0624.
nvd
CVE-2020-0624HIGHCVSS 7.8PoCv1903v19092020-01-14
CVE-2020-0624 [HIGH] CVE-2020-0624: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0642.
nvd
CVE-2020-0628HIGHCVSS 7.8v1607v1709+4 more2020-01-14
CVE-2020-0628 [HIGH] CVE-2020-0628: An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles ob An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CV
nvd
CVE-2020-0631HIGHCVSS 7.8v1607v1709+4 more2020-01-14
CVE-2020-0631 [HIGH] CVE-2020-0631: An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles ob An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0632, CV
nvd
CVE-2020-0633HIGHCVSS 7.8v1607v1709+4 more2020-01-14
CVE-2020-0633 [HIGH] CVE-2020-0633: An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles ob An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CV
nvd
CVE-2020-0627HIGHCVSS 7.8v1607v1709+4 more2020-01-14
CVE-2020-0627 [HIGH] CVE-2020-0627: An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles ob An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CV
nvd