Microsoft Windows 10 vulnerabilities
2,804 known vulnerabilities affecting microsoft/windows_10.
Total CVEs
2,804
CISA KEV
7
actively exploited
Public exploits
216
Exploited in wild
26
Severity breakdown
CRITICAL68HIGH1907MEDIUM802LOW27
Vulnerabilities
Page 89 of 141
CVE-2019-1320HIGHCVSS 7.8v1709v1803+2 more2019-10-10
CVE-2019-1320 [HIGH] CVE-2019-1320: An elevation of privilege vulnerability exists when Windows improperly handles authentication reques
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1322, CVE-2019-1340.
nvd
CVE-2019-1316HIGHCVSS 7.8v1607v1703+4 more2019-10-10
CVE-2019-1316 [HIGH] CVE-2019-1316: An elevation of privilege vulnerability exists in Microsoft Windows Setup when it does not properly
An elevation of privilege vulnerability exists in Microsoft Windows Setup when it does not properly handle privileges, aka 'Microsoft Windows Setup Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1339HIGHCVSS 7.8v1607v1703+4 more2019-10-10
CVE-2019-1339 [HIGH] CVE-2019-1339: An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handl
An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1315, CVE-2019-1342.
nvd
CVE-2019-1341HIGHCVSS 7.8v1607v1703+4 more2019-10-10
CVE-2019-1341 [HIGH] CVE-2019-1341: An elevation of privilege vulnerability exists when umpo.dll of the Power Service, improperly handle
An elevation of privilege vulnerability exists when umpo.dll of the Power Service, improperly handles a Registry Restore Key function, aka 'Windows Power Service Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1359HIGHCVSS 7.8v1607v1703+4 more2019-10-10
CVE-2019-1359 [HIGH] CVE-2019-1359: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1358.
nvd
CVE-2019-1333HIGHCVSS 8.8v1607v1703+4 more2019-10-10
CVE-2019-1333 [HIGH] CVE-2019-1333: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.
nvd
CVE-2019-1340HIGHCVSS 7.8v1703v1709+3 more2019-10-10
CVE-2019-1340 [HIGH] CVE-2019-1340: An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file cr
An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1320, CVE-2019-1322.
nvd
CVE-2019-1060HIGHCVSS 8.8v1607v1703+4 more2019-10-10
CVE-2019-1060 [HIGH] CWE-611 CVE-2019-1060: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.
nvd
CVE-2019-1323HIGHCVSS 7.8v1809v19032019-10-10
CVE-2019-1323 [HIGH] CVE-2019-1323: An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does n
An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does not properly handle privileges, aka 'Microsoft Windows Update Client Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1336.
nvd
CVE-2019-1321HIGHCVSS 7.8v1703v1709+3 more2019-10-10
CVE-2019-1321 [HIGH] CVE-2019-1321: An elevation of privilege vulnerability exists when Windows CloudStore improperly handles file Discr
An elevation of privilege vulnerability exists when Windows CloudStore improperly handles file Discretionary Access Control List (DACL), aka 'Microsoft Windows CloudStore Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1317HIGHCVSS 7.3v1607v1703+4 more2019-10-10
CVE-2019-1317 [HIGH] CWE-59 CVE-2019-1317: A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft
A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.
nvd
CVE-2019-1326HIGHCVSS 7.5v1607v1703+4 more2019-10-10
CVE-2019-1326 [HIGH] CVE-2019-1326: A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
nvd
CVE-2019-1358HIGHCVSS 7.8v1607v1703+4 more2019-10-10
CVE-2019-1358 [HIGH] CVE-2019-1358: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1359.
nvd
CVE-2019-1336HIGHCVSS 7.8v1809v19032019-10-10
CVE-2019-1336 [HIGH] CVE-2019-1336: An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does n
An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does not properly handle privileges, aka 'Microsoft Windows Update Client Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1323.
nvd
CVE-2019-1311HIGHCVSS 7.8v1607v1703+4 more2019-10-10
CVE-2019-1311 [HIGH] CVE-2019-1311: A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects
A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects in memory, aka 'Windows Imaging API Remote Code Execution Vulnerability'.
nvd
CVE-2019-1342HIGHCVSS 7.8v1607v1703+4 more2019-10-10
CVE-2019-1342 [HIGH] CVE-2019-1342: An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handl
An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1315, CVE-2019-1339.
nvd
CVE-2019-1319HIGHCVSS 7.8v1607v1703+4 more2019-10-10
CVE-2019-1319 [HIGH] CVE-2019-1319: An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1318MEDIUMCVSS 5.9v1607v1703+4 more2019-10-10
CVE-2019-1318 [MEDIUM] CWE-290 CVE-2019-1318: A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Se
A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions, aka 'Microsoft Windows Transport Layer Security Spoofing Vulnerability'.
nvd
CVE-2019-1368MEDIUMCVSS 4.6v1803v1809+1 more2019-10-10
CVE-2019-1368 [MEDIUM] CVE-2019-1368: A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging f
A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging functionality, aka 'Windows Secure Boot Security Feature Bypass Vulnerability'.
nvd
CVE-2019-1343MEDIUMCVSS 6.5PoCv1607v1703+4 more2019-10-10
CVE-2019-1343 [MEDIUM] CVE-2019-1343: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1346, CVE-2019-1347.
nvd