Microsoft Windows 10 1507 vulnerabilities
1,047 known vulnerabilities affecting microsoft/windows_10_1507.
Total CVEs
1,047
CISA KEV
74
actively exploited
Public exploits
44
Exploited in wild
83
Severity breakdown
CRITICAL32HIGH730MEDIUM280LOW5
Vulnerabilities
Page 43 of 53
CVE-2023-28222P4HIGHCVSS 7.1fixed in 10.0.10240.198692023-04-11
CVE-2023-28222 [HIGH] CWE-59 CVE-2023-28222: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-28267P4MEDIUMCVSS 6.5fixed in 10.0.10240.198692023-04-11
CVE-2023-28267 [MEDIUM] CWE-126 CVE-2023-28267: Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability
nvd
CVE-2023-28224P4HIGHCVSS 7.1fixed in 10.0.10240.198692023-04-11
CVE-2023-28224 [HIGH] CWE-591 CVE-2023-28224: Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
nvd
CVE-2023-23407P4HIGHCVSS 7.1fixed in 10.0.10240.198052023-03-14
CVE-2023-23407 [HIGH] CWE-591 CVE-2023-23407: Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
nvd
CVE-2023-23414P4HIGHCVSS 7.1fixed in 10.0.10240.198052023-03-14
CVE-2023-23414 [HIGH] CWE-591 CVE-2023-23414: Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
nvd
CVE-2024-43534P4MEDIUMCVSS 6.5fixed in 10.0.10240.207962024-10-08
CVE-2024-43534 [MEDIUM] CWE-125 CVE-2024-43534: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2025-50158P4HIGHCVSS 7.0fixed in 10.0.10240.211002025-08-12
CVE-2025-50158 [HIGH] CWE-367 CVE-2025-50158: Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to
Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to disclose information locally.
nvd
CVE-2023-29368P4HIGHCVSS 7.0fixed in 10.0.10240.199832023-06-14
CVE-2023-29368 [HIGH] CWE-415 CVE-2023-29368: Windows Filtering Platform Elevation of Privilege Vulnerability
Windows Filtering Platform Elevation of Privilege Vulnerability
nvd
CVE-2023-28216P4HIGHCVSS 7.0fixed in 10.0.10240.198692023-04-11
CVE-2023-28216 [HIGH] CVE-2023-28216: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
nvd
CVE-2023-23385P4HIGHCVSS 7.0fixed in 10.0.10240.198052023-03-14
CVE-2023-23385 [HIGH] CWE-190 CVE-2023-23385: Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability
Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability
nvd
CVE-2025-48800P4MEDIUMCVSS 6.8fixed in 10.0.10240.210732025-07-08
CVE-2025-48800 [MEDIUM] CWE-693 CVE-2025-48800: Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a securi
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48804P4MEDIUMCVSS 6.8fixed in 10.0.10240.210732025-07-08
CVE-2025-48804 [MEDIUM] CWE-349 CVE-2025-48804: Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorize
Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48818P4MEDIUMCVSS 6.8fixed in 10.0.10240.210732025-07-08
CVE-2025-48818 [MEDIUM] CWE-367 CVE-2025-48818: Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attack
Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48001P4MEDIUMCVSS 6.8fixed in 10.0.10240.210732025-07-08
CVE-2025-48001 [MEDIUM] CWE-367 CVE-2025-48001: Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attack
Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2024-21430P4MEDIUMCVSS 6.4fixed in 10.0.10240.205262024-03-12
CVE-2024-21430 [MEDIUM] CWE-125 CVE-2024-21430: Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability
Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability
nvd
CVE-2025-27471P4MEDIUMCVSS 5.9fixed in 10.0.10240.209782025-04-08
CVE-2025-27471 [MEDIUM] CWE-591 CVE-2025-27471: Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthor
Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2023-36713P4MEDIUMCVSS 5.5fixed in 10.0.10240.202322023-10-10
CVE-2023-36713 [MEDIUM] CWE-908 CVE-2023-36713: Windows Common Log File System Driver Information Disclosure Vulnerability
Windows Common Log File System Driver Information Disclosure Vulnerability
nvd
CVE-2025-27472P4MEDIUMCVSS 5.4fixed in 10.0.10240.209782025-04-08
CVE-2025-27472 [MEDIUM] CWE-693 CVE-2025-27472: Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to by
Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2022-26934P4MEDIUMCVSS 6.5fixed in 10.0.10240.192972022-05-10
CVE-2022-26934 [MEDIUM] CVE-2022-26934: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2023-35318P4MEDIUMCVSS 6.5fixed in 10.0.10240.200482023-07-11
CVE-2023-35318 [MEDIUM] CWE-125 CVE-2023-35318: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd