cbcvebase.

Microsoft Windows 10 1607 vulnerabilities

1,426 known vulnerabilities affecting microsoft/windows_10_1607.

Total CVEs
1,426
CISA KEV
86
actively exploited
Public exploits
36
Exploited in wild
59
Severity breakdown
CRITICAL39HIGH1015MEDIUM366LOW6

Vulnerabilities

Page 1 of 72
CVE-2026-34333HIGHCVSS 7.8fixed in 10.0.14393.91402026-05-12
CVE-2026-34333 [HIGH] CWE-190 CVE-2026-34333: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-35415HIGHCVSS 7.8fixed in 10.0.14393.91402026-05-12
CVE-2026-35415 [HIGH] CWE-190 CVE-2026-35415: Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34330HIGHCVSS 7.8fixed in 10.0.14393.91402026-05-12
CVE-2026-34330 [HIGH] CWE-190 CVE-2026-34330: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-33837HIGHCVSS 7.8fixed in 10.0.14393.91402026-05-12
CVE-2026-33837 [HIGH] CWE-122 CVE-2026-33837: Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges loc Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40403HIGHCVSS 8.8fixed in 10.0.14393.91402026-05-12
CVE-2026-40403 [HIGH] CWE-122 CVE-2026-40403: Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code lo Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
nvd
CVE-2026-32161HIGHCVSS 7.5fixed in 10.0.14393.91402026-05-12
CVE-2026-32161 [HIGH] CWE-362 CVE-2026-32161: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthorized attacker to execute code over an adjacent network.
nvd
CVE-2026-34329HIGHCVSS 8.8fixed in 10.0.14393.91402026-05-12
CVE-2026-34329 [HIGH] CWE-122 CVE-2026-34329: Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute cod Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network.
nvd
CVE-2026-40401HIGHCVSS 7.1fixed in 10.0.14393.91402026-05-12
CVE-2026-40401 [HIGH] CWE-476 CVE-2026-40401: Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service locally. Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service locally.
nvd
CVE-2026-34338HIGHCVSS 7.8fixed in 10.0.14393.91402026-05-12
CVE-2026-34338 [HIGH] CWE-416 CVE-2026-34338: Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges loca Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34336HIGHCVSS 7.8fixed in 10.0.14393.91402026-05-12
CVE-2026-34336 [HIGH] CWE-122 CVE-2026-34336: Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40398HIGHCVSS 7.8fixed in 10.0.14393.91402026-05-12
CVE-2026-40398 [HIGH] CWE-122 CVE-2026-40398: Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privil Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34347HIGHCVSS 7.0fixed in 10.0.14393.91402026-05-12
CVE-2026-34347 [HIGH] CWE-416 CVE-2026-34347: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34343HIGHCVSS 7.8fixed in 10.0.14393.91402026-05-12
CVE-2026-34343 [HIGH] CWE-122 CVE-2026-34343: Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized at Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40410HIGHCVSS 7.0fixed in 10.0.14393.91402026-05-12
CVE-2026-40410 [HIGH] CWE-416 CVE-2026-40410: Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally. Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40377HIGHCVSS 7.8fixed in 10.0.14393.91402026-05-12
CVE-2026-40377 [HIGH] CWE-122 CVE-2026-40377: Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevat Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-35424HIGHCVSS 7.5fixed in 10.0.14393.91402026-05-12
CVE-2026-35424 [HIGH] CWE-401 CVE-2026-35424: Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol a Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-34341HIGHCVSS 7.0fixed in 10.0.14393.91402026-05-12
CVE-2026-34341 [HIGH] CWE-415 CVE-2026-34341: Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-33838HIGHCVSS 7.8fixed in 10.0.14393.91402026-05-12
CVE-2026-33838 [HIGH] CWE-415 CVE-2026-33838: Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally. Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34345HIGHCVSS 7.0fixed in 10.0.14393.91402026-05-12
CVE-2026-34345 [HIGH] CWE-362 CVE-2026-34345: Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver f Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40408HIGHCVSS 7.8fixed in 10.0.14393.91402026-05-12
CVE-2026-40408 [HIGH] CWE-416 CVE-2026-40408: Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges lo Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
nvd
1 / 72Next →
Microsoft Windows 10 1607 vulnerabilities | cvebase