Microsoft Windows 10 1809 vulnerabilities
2,099 known vulnerabilities affecting microsoft/windows_10_1809.
Total CVEs
2,099
CISA KEV
100
actively exploited
Public exploits
62
Exploited in wild
111
Severity breakdown
CRITICAL63HIGH1493MEDIUM535LOW8
Vulnerabilities
Page 47 of 105
CVE-2024-37982P3HIGHCVSS 7.8fixed in 10.0.17763.64142024-10-08
CVE-2024-37982 [HIGH] CWE-822 CVE-2024-37982: Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
nvd
CVE-2025-24058P3HIGHCVSS 7.8fixed in 10.0.17763.71362025-04-08
CVE-2025-24058 [HIGH] CWE-20 CVE-2025-24058: Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privi
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24074P3HIGHCVSS 7.8fixed in 10.0.17763.71362025-04-08
CVE-2025-24074 [HIGH] CWE-20 CVE-2025-24074: Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privi
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24060P3HIGHCVSS 7.8fixed in 10.0.17763.71362025-04-08
CVE-2025-24060 [HIGH] CWE-20 CVE-2025-24060: Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privi
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24073P3HIGHCVSS 7.8fixed in 10.0.17763.71362025-04-08
CVE-2025-24073 [HIGH] CWE-20 CVE-2025-24073: Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privi
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-47656P3HIGHCVSS 7.9fixed in 10.0.17763.88802026-06-09
CVE-2026-47656 [HIGH] CWE-693 CVE-2026-47656: Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a secur
Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2025-60709P3HIGHCVSS 7.8fixed in 10.0.17763.80272025-11-11
CVE-2025-60709 [HIGH] CWE-125 CVE-2025-60709: Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate
Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24046P3HIGHCVSS 7.8fixed in 10.0.17763.70092025-03-11
CVE-2025-24046 [HIGH] CWE-416 CVE-2025-24046: Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges lo
Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20832P3HIGHCVSS 7.8fixed in 10.0.17763.82762026-01-13
CVE-2026-20832 [HIGH] CWE-415 CVE-2026-20832: Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerabili
Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability
nvd
CVE-2026-20857P3HIGHCVSS 7.8fixed in 10.0.17763.82762026-01-13
CVE-2026-20857 [HIGH] CWE-822 CVE-2026-20857: Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacke
Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-32712P3HIGHCVSS 7.8fixed in 10.0.17763.74342025-06-10
CVE-2025-32712 [HIGH] CWE-416 CVE-2025-32712: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53726P3HIGHCVSS 7.8fixed in 10.0.17763.76782025-08-12
CVE-2025-53726 [HIGH] CWE-843 CVE-2025-53726: Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows a
Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53724P3HIGHCVSS 7.8fixed in 10.0.17763.76782025-08-12
CVE-2025-53724 [HIGH] CWE-843 CVE-2025-53724: Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows a
Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50155P3HIGHCVSS 7.8fixed in 10.0.17763.76782025-08-12
CVE-2025-50155 [HIGH] CWE-122 CVE-2025-50155: Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows a
Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53725P3HIGHCVSS 7.8fixed in 10.0.17763.76782025-08-12
CVE-2025-53725 [HIGH] CWE-843 CVE-2025-53725: Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows a
Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54102P3HIGHCVSS 7.8fixed in 10.0.17763.77922025-09-09
CVE-2025-54102 [HIGH] CWE-416 CVE-2025-54102: Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevat
Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-33838P3HIGHCVSS 7.8fixed in 10.0.17763.87552026-05-12
CVE-2026-33838 [HIGH] CWE-415 CVE-2026-33838: Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50152P3HIGHCVSS 7.8fixed in 10.0.17763.79192025-10-14
CVE-2025-50152 [HIGH] CWE-125 CVE-2025-50152: Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50170P3HIGHCVSS 7.8fixed in 10.0.17763.76782025-08-12
CVE-2025-50170 [HIGH] CWE-280 CVE-2025-50170: Improper handling of insufficient permissions or privileges in Windows Cloud Files Mini Filter Drive
Improper handling of insufficient permissions or privileges in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59505P3HIGHCVSS 7.8fixed in 10.0.17763.80272025-11-11
CVE-2025-59505 [HIGH] CWE-415 CVE-2025-59505: Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally.
Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally.
nvd