Microsoft Windows 10 1809 vulnerabilities
2,099 known vulnerabilities affecting microsoft/windows_10_1809.
Total CVEs
2,099
CISA KEV
100
actively exploited
Public exploits
62
Exploited in wild
111
Severity breakdown
CRITICAL63HIGH1493MEDIUM535LOW8
Vulnerabilities
Page 44 of 105
CVE-2026-32078P3HIGHCVSS 7.8fixed in 10.0.17763.86442026-04-14
CVE-2026-32078 [HIGH] CWE-416 CVE-2026-32078: Use after free in Windows Projected File System allows an authorized attacker to elevate privileges
Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32074P3HIGHCVSS 7.8fixed in 10.0.17763.86442026-04-14
CVE-2026-32074 [HIGH] CWE-415 CVE-2026-32074: Double free in Windows Projected File System allows an authorized attacker to elevate privileges loc
Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32069P3HIGHCVSS 7.8fixed in 10.0.17763.86442026-04-14
CVE-2026-32069 [HIGH] CWE-415 CVE-2026-32069: Double free in Windows Projected File System allows an authorized attacker to elevate privileges loc
Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59278P3HIGHCVSS 7.8fixed in 10.0.17763.79192025-10-14
CVE-2025-59278 [HIGH] CWE-1287 CVE-2025-59278: Improper validation of specified type of input in Windows Authentication Methods allows an authorize
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59275P3HIGHCVSS 7.8fixed in 10.0.17763.79192025-10-14
CVE-2025-59275 [HIGH] CWE-122 CVE-2025-59275: Improper validation of specified type of input in Windows Authentication Methods allows an authorize
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42978P3HIGHCVSS 7.8fixed in 10.0.17763.88802026-06-09
CVE-2026-42978 [HIGH] CWE-362 CVE-2026-42978: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32089P3HIGHCVSS 7.8fixed in 10.0.17763.86442026-04-14
CVE-2026-32089 [HIGH] CWE-362 CVE-2026-32089: Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges lo
Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50311P3HIGHCVSS 7.8fixed in 10.0.17763.90202026-07-14
CVE-2026-50311 [HIGH] CWE-284 CVE-2026-50311: Improper access control in Windows Server allows an authorized attacker to elevate privileges locall
Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59502P3HIGHCVSS 7.5fixed in 10.0.17763.77922025-10-14
CVE-2025-59502 [HIGH] CWE-400 CVE-2025-59502: Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker t
Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-54109P3HIGHCVSS 7.8fixed in 10.0.17763.90202026-07-14
CVE-2026-54109 [HIGH] CWE-122 CVE-2026-54109: Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker
Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
nvd
CVE-2026-27916P3HIGHCVSS 7.8fixed in 10.0.17763.86442026-04-14
CVE-2026-27916 [HIGH] CWE-416 CVE-2026-27916: Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker t
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-64661P3HIGHCVSS 7.8fixed in 10.0.17763.81462025-12-09
CVE-2025-64661 [HIGH] CWE-362 CVE-2025-64661: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-27923P3HIGHCVSS 7.8fixed in 10.0.17763.86442026-04-14
CVE-2026-27923 [HIGH] CWE-416 CVE-2026-27923: Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49171P3HIGHCVSS 7.8fixed in 10.0.17763.90202026-07-14
CVE-2026-49171 [HIGH] CWE-416 CVE-2026-49171: Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges local
Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-55001P3HIGHCVSS 7.8fixed in 10.0.17763.90202026-07-14
CVE-2026-55001 [HIGH] CWE-295 CVE-2026-55001: Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate
Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50405P3HIGHCVSS 7.8fixed in 10.0.17763.90202026-07-14
CVE-2026-50405 [HIGH] CWE-1220 CVE-2026-50405: Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized
Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32160P3HIGHCVSS 7.8fixed in 10.0.17763.86442026-04-14
CVE-2026-32160 [HIGH] CWE-362 CVE-2026-32160: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32159P3HIGHCVSS 7.8fixed in 10.0.17763.86442026-04-14
CVE-2026-32159 [HIGH] CWE-362 CVE-2026-32159: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32158P3HIGHCVSS 7.8fixed in 10.0.17763.86442026-04-14
CVE-2026-32158 [HIGH] CWE-362 CVE-2026-32158: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32153P3HIGHCVSS 7.8fixed in 10.0.17763.86442026-04-14
CVE-2026-32153 [HIGH] CWE-362 CVE-2026-32153: Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges local
Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
nvd