Microsoft Windows 10 vulnerabilities

2,804 known vulnerabilities affecting microsoft/windows_10.

Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
216
Exploited in wild
26
Severity breakdown
CRITICAL68HIGH1907MEDIUM802LOW27

Vulnerabilities

Page 87 of 141
CVE-2019-1433HIGHCVSS 7.8v1607v1709+3 more2019-11-12
CVE-2019-1433 [HIGH] CVE-2019-1433: An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handle An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1407, CVE-2019-1435, CVE-2019-1437, CVE-2019-1438.
nvd
CVE-2019-1430HIGHCVSS 7.8v19032019-11-12
CVE-2019-1430 [HIGH] CVE-2019-1430: A remote code execution vulnerability exists when Windows Media Foundation improperly parses special A remote code execution vulnerability exists when Windows Media Foundation improperly parses specially crafted QuickTime media files.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'Microsoft Windows Media Foundation Remote Code Execution Vulnerability'.
nvd
CVE-2019-1406HIGHCVSS 7.8v1607v1709+3 more2019-11-12
CVE-2019-1406 [HIGH] CVE-2019-1406: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.
nvd
CVE-2019-1408HIGHCVSS 7.8v1607v1709+3 more2019-11-12
CVE-2019-1408 [HIGH] CVE-2019-1408: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1393, CVE-2019-1394, CVE-2019-1395, CVE-2019-1396, CVE-2019-1434.
nvd
CVE-2019-1415HIGHCVSS 7.8v1607v1709+3 more2019-11-12
CVE-2019-1415 [HIGH] CVE-2019-1415: An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Insta An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1379HIGHCVSS 7.8v18092019-11-12
CVE-2019-1379 [HIGH] CVE-2019-1379: An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly hand An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka 'Windows Data Sharing Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1383, CVE-2019-1417.
nvd
CVE-2019-1420HIGHCVSS 7.8v1607v1709+3 more2019-11-12
CVE-2019-1420 [HIGH] CVE-2019-1420: An elevation of privilege vulnerability exists in the way that the dssvc.dll handles file creation a An elevation of privilege vulnerability exists in the way that the dssvc.dll handles file creation allowing for a file overwrite or creation in a secured location, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1422, CVE-2019-1423.
nvd
CVE-2019-1396HIGHCVSS 7.8v1607v1709+3 more2019-11-12
CVE-2019-1396 [HIGH] CVE-2019-1396: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1393, CVE-2019-1394, CVE-2019-1395, CVE-2019-1408, CVE-2019-1434.
nvd
CVE-2019-1438HIGHCVSS 7.8v1607v1709+3 more2019-11-12
CVE-2019-1438 [HIGH] CVE-2019-1438: An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handle An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1407, CVE-2019-1433, CVE-2019-1435, CVE-2019-1437.
nvd
CVE-2019-1389HIGHCVSS 8.4v1607v1709+1 more2019-11-12
CVE-2019-1389 [HIGH] CWE-20 CVE-2019-1389: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1397, CVE-2019-1398.
nvd
CVE-2019-1395HIGHCVSS 7.8v1607v1709+3 more2019-11-12
CVE-2019-1395 [HIGH] CVE-2019-1395: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1393, CVE-2019-1394, CVE-2019-1396, CVE-2019-1408, CVE-2019-1434.
nvd
CVE-2019-1422HIGHCVSS 7.8v1607v1709+3 more2019-11-12
CVE-2019-1422 [HIGH] CVE-2019-1422: An elevation of privilege vulnerability exists in the way that the iphlpsvc.dll handles file creatio An elevation of privilege vulnerability exists in the way that the iphlpsvc.dll handles file creation allowing for a file overwrite, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1420, CVE-2019-1423.
nvd
CVE-2019-1437HIGHCVSS 7.8v1809v19032019-11-12
CVE-2019-1437 [HIGH] CVE-2019-1437: An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handle An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1407, CVE-2019-1433, CVE-2019-1435, CVE-2019-1438.
nvd
CVE-2019-1416HIGHCVSS 7.0v1709v1803+2 more2019-11-12
CVE-2019-1416 [HIGH] CWE-362 CVE-2019-1416: An elevation of privilege vulnerability exists due to a race condition in Windows Subsystem for Linu An elevation of privilege vulnerability exists due to a race condition in Windows Subsystem for Linux, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1423HIGHCVSS 7.8v19032019-11-12
CVE-2019-1423 [HIGH] CVE-2019-1423: An elevation of privilege vulnerability exists in the way that the StartTileData.dll handles file cr An elevation of privilege vulnerability exists in the way that the StartTileData.dll handles file creation in protected locations, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1420, CVE-2019-1422.
nvd
CVE-2019-1394HIGHCVSS 7.8v1607v1709+3 more2019-11-12
CVE-2019-1394 [HIGH] CVE-2019-1394: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1393, CVE-2019-1395, CVE-2019-1396, CVE-2019-1408, CVE-2019-1434.
nvd
CVE-2019-1407HIGHCVSS 7.8v1607v1709+1 more2019-11-12
CVE-2019-1407 [HIGH] CVE-2019-1407: An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handle An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1433, CVE-2019-1435, CVE-2019-1437, CVE-2019-1438.
nvd
CVE-2019-1424HIGHCVSS 8.1v1607v1709+3 more2019-11-12
CVE-2019-1424 [HIGH] CVE-2019-1424: A security feature bypass vulnerability exists when Windows Netlogon improperly handles a secure com A security feature bypass vulnerability exists when Windows Netlogon improperly handles a secure communications channel, aka 'NetLogon Security Feature Bypass Vulnerability'.
nvd
CVE-2019-1380HIGHCVSS 7.8v1607v1709+3 more2019-11-12
CVE-2019-1380 [HIGH] CWE-367 CVE-2019-1380: A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka ' A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1397HIGHCVSS 8.4v1607v1709+3 more2019-11-12
CVE-2019-1397 [HIGH] CVE-2019-1397: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1389, CVE-2019-1398.
nvd