Microsoft Windows 10 1607 vulnerabilities
1,753 known vulnerabilities affecting microsoft/windows_10_1607.
Total CVEs
1,753
CISA KEV
87
actively exploited
Public exploits
53
Exploited in wild
99
Severity breakdown
CRITICAL61HIGH1246MEDIUM437LOW9
Vulnerabilities
Page 82 of 88
CVE-2025-55333P4MEDIUMCVSS 4.6fixed in 10.0.14393.85192025-10-14
CVE-2025-55333 [MEDIUM] CWE-1023 CVE-2025-55333: Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to b
Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2026-50661P4MEDIUMCVSS 4.6fixed in 10.0.14393.93392026-07-14
CVE-2026-50661 [MEDIUM] CWE-693 CVE-2026-50661: Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a securi
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2023-36908P4MEDIUMCVSS 6.5fixed in 10.0.14393.61672023-08-08
CVE-2023-36908 [MEDIUM] CWE-200 CVE-2023-36908: Windows Hyper-V Information Disclosure Vulnerability
Windows Hyper-V Information Disclosure Vulnerability
nvd
CVE-2025-24992P4MEDIUMCVSS 5.5fixed in 10.0.14393.78762025-03-11
CVE-2025-24992 [MEDIUM] CWE-126 CVE-2025-24992: Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.
nvd
CVE-2024-38256P4MEDIUMCVSS 5.5fixed in 10.0.14393.73362024-09-10
CVE-2024-38256 [MEDIUM] CWE-908 CVE-2024-38256: Windows Kernel-Mode Driver Information Disclosure Vulnerability
Windows Kernel-Mode Driver Information Disclosure Vulnerability
nvd
CVE-2024-43554P4MEDIUMCVSS 5.5fixed in 10.0.14393.74282024-10-08
CVE-2024-43554 [MEDIUM] CWE-212 CVE-2024-43554: Windows Kernel-Mode Driver Information Disclosure Vulnerability
Windows Kernel-Mode Driver Information Disclosure Vulnerability
nvd
CVE-2023-21699P4MEDIUMCVSS 5.3fixed in 10.0.14393.57172023-02-14
CVE-2023-21699 [MEDIUM] CWE-125 CVE-2023-21699: Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability
Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability
nvd
CVE-2025-33055P4MEDIUMCVSS 5.5fixed in 10.0.14393.81482025-06-10
CVE-2025-33055 [MEDIUM] CWE-125 CVE-2025-33055: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-33062P4MEDIUMCVSS 5.5fixed in 10.0.14393.81482025-06-10
CVE-2025-33062 [MEDIUM] CWE-125 CVE-2025-33062: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-33061P4MEDIUMCVSS 5.5fixed in 10.0.14393.81482025-06-10
CVE-2025-33061 [MEDIUM] CWE-125 CVE-2025-33061: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-24069P4MEDIUMCVSS 5.5fixed in 10.0.14393.81482025-06-10
CVE-2025-24069 [MEDIUM] CWE-125 CVE-2025-24069: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-33058P4MEDIUMCVSS 5.5fixed in 10.0.14393.81482025-06-10
CVE-2025-33058 [MEDIUM] CWE-125 CVE-2025-33058: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-33060P4MEDIUMCVSS 5.5fixed in 10.0.14393.81482025-06-10
CVE-2025-33060 [MEDIUM] CWE-125 CVE-2025-33060: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-33059P4MEDIUMCVSS 5.5fixed in 10.0.14393.81482025-06-10
CVE-2025-33059 [MEDIUM] CWE-125 CVE-2025-33059: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-33065P4MEDIUMCVSS 5.5fixed in 10.0.14393.81482025-06-10
CVE-2025-33065 [MEDIUM] CWE-125 CVE-2025-33065: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-32719P4MEDIUMCVSS 5.5fixed in 10.0.14393.81482025-06-10
CVE-2025-32719 [MEDIUM] CWE-125 CVE-2025-32719: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-49658P4MEDIUMCVSS 5.5fixed in 10.0.14393.82462025-07-08
CVE-2025-49658 [MEDIUM] CWE-125 CVE-2025-49658: Out-of-bounds read in Windows TDX.sys allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows TDX.sys allows an authorized attacker to disclose information locally.
nvd
CVE-2026-25169P4MEDIUMCVSS 5.5fixed in 10.0.14393.89572026-03-10
CVE-2026-25169 [MEDIUM] CWE-369 CVE-2026-25169: Divide by zero in Microsoft Graphics Component allows an unauthorized attacker to deny service local
Divide by zero in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.
nvd
CVE-2025-29829P4MEDIUMCVSS 5.5fixed in 10.0.14393.80662025-05-13
CVE-2025-29829 [MEDIUM] CWE-908 CVE-2025-29829: Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attac
Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2025-21268P4MEDIUMCVSS 4.3fixed in 10.0.14393.76992025-01-14
CVE-2025-21268 [MEDIUM] CWE-41 CVE-2025-21268: MapUrlToZone Security Feature Bypass Vulnerability
MapUrlToZone Security Feature Bypass Vulnerability
nvd