Microsoft Windows 10 1507 vulnerabilities
1,047 known vulnerabilities affecting microsoft/windows_10_1507.
Total CVEs
1,047
CISA KEV
74
actively exploited
Public exploits
44
Exploited in wild
83
Severity breakdown
CRITICAL32HIGH730MEDIUM280LOW5
Vulnerabilities
Page 29 of 53
CVE-2024-43514P3HIGHCVSS 7.8fixed in 10.0.10240.207962024-10-08
CVE-2024-43514 [HIGH] CWE-415 CVE-2024-43514: Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
nvd
CVE-2023-36729P3HIGHCVSS 7.8fixed in 10.0.10240.202322023-10-10
CVE-2023-36729 [HIGH] CWE-121 CVE-2023-36729: Named Pipe File System Elevation of Privilege Vulnerability
Named Pipe File System Elevation of Privilege Vulnerability
nvd
CVE-2025-21378P3HIGHCVSS 7.8fixed in 10.0.10240.208902025-01-14
CVE-2025-21378 [HIGH] CWE-122 CVE-2025-21378: Windows CSC Service Elevation of Privilege Vulnerability
Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2024-43644P3HIGHCVSS 7.8fixed in 10.0.10240.208262024-11-12
CVE-2024-43644 [HIGH] CWE-125 CVE-2024-43644: Windows Client-Side Caching Elevation of Privilege Vulnerability
Windows Client-Side Caching Elevation of Privilege Vulnerability
nvd
CVE-2024-43645P3HIGHCVSS 7.8fixed in 10.0.10240.208262024-11-12
CVE-2024-43645 [HIGH] CWE-693 CVE-2024-43645: Windows Defender Application Control (WDAC) Security Feature Bypass Vulnerability
Windows Defender Application Control (WDAC) Security Feature Bypass Vulnerability
nvd
CVE-2025-32716P3HIGHCVSS 7.8fixed in 10.0.10240.210342025-06-10
CVE-2025-32716 [HIGH] CWE-125 CVE-2025-32716: Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-49046P3HIGHCVSS 7.8fixed in 10.0.10240.208262024-11-12
CVE-2024-49046 [HIGH] CWE-367 CVE-2024-49046: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2024-26228P3HIGHCVSS 7.8fixed in 10.0.10240.205962024-04-09
CVE-2024-26228 [HIGH] CWE-310 CVE-2024-26228: Windows Cryptographic Services Security Feature Bypass Vulnerability
Windows Cryptographic Services Security Feature Bypass Vulnerability
nvd
CVE-2025-49686P3HIGHCVSS 7.8fixed in 10.0.10240.210732025-07-08
CVE-2025-49686 [HIGH] CWE-476 CVE-2025-49686: Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges local
Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-47985P3HIGHCVSS 7.8fixed in 10.0.10240.210732025-07-08
CVE-2025-47985 [HIGH] CWE-822 CVE-2025-47985: Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate priv
Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49661P3HIGHCVSS 7.8fixed in 10.0.10240.210732025-07-08
CVE-2025-49661 [HIGH] CWE-822 CVE-2025-49661: Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized
Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55230P3HIGHCVSS 7.8fixed in 10.0.10240.210732025-08-21
CVE-2025-55230 [HIGH] CWE-822 CVE-2025-55230: Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to eleva
Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-27738P3MEDIUMCVSS 6.5fixed in 10.0.10240.209782025-04-08
CVE-2025-27738 [MEDIUM] CWE-284 CVE-2025-27738: Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to dis
Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network.
nvd
CVE-2025-29842P3HIGHCVSS 7.5fixed in 10.0.10240.210142025-05-13
CVE-2025-29842 [HIGH] CWE-349 CVE-2025-29842: Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker
Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2025-25004P3HIGHCVSS 7.3fixed in 10.0.10240.211612025-10-14
CVE-2025-25004 [HIGH] CWE-284 CVE-2025-25004: Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges
Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-35743P3HIGHCVSS 7.8fixed in 10.0.10240.193872023-05-31
CVE-2022-35743 [HIGH] CWE-94 CVE-2022-35743: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
nvd
CVE-2023-36596P3HIGHCVSS 7.5fixed in 10.0.10240.202322023-10-10
CVE-2023-36596 [HIGH] CWE-822 CVE-2023-36596: Remote Procedure Call Information Disclosure Vulnerability
Remote Procedure Call Information Disclosure Vulnerability
nvd
CVE-2023-36710P3HIGHCVSS 7.8fixed in 10.0.10240.202322023-10-10
CVE-2023-36710 [HIGH] CWE-197 CVE-2023-36710: Windows Media Foundation Core Remote Code Execution Vulnerability
Windows Media Foundation Core Remote Code Execution Vulnerability
nvd
CVE-2023-36438P3HIGHCVSS 7.5fixed in 10.0.10240.202322023-10-10
CVE-2023-36438 [HIGH] CVE-2023-36438: Windows TCP/IP Information Disclosure Vulnerability
Windows TCP/IP Information Disclosure Vulnerability
nvd
CVE-2023-36436P3HIGHCVSS 7.8fixed in 10.0.10240.202322023-10-10
CVE-2023-36436 [HIGH] CVE-2023-36436: Windows MSHTML Platform Remote Code Execution Vulnerability
Windows MSHTML Platform Remote Code Execution Vulnerability
nvd