Microsoft Windows 10 20H2 vulnerabilities

210 known vulnerabilities affecting microsoft/windows_10_20h2.

Total CVEs
210
CISA KEV
43
actively exploited
Public exploits
8
Exploited in wild
43
Severity breakdown
CRITICAL11HIGH156MEDIUM43

Vulnerabilities

Page 2 of 11
CVE-2023-24903HIGHCVSS 8.1fixed in 10.0.19042.29652023-05-09
CVE-2023-24903 [HIGH] CWE-415 CVE-2023-24903: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2023-28283HIGHCVSS 8.1fixed in 10.0.19042.29652023-05-09
CVE-2023-28283 [HIGH] CWE-591 CVE-2023-28283: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2023-24905HIGHCVSS 7.8fixed in 10.0.19042.29652023-05-09
CVE-2023-24905 [HIGH] CWE-284 CVE-2023-24905: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2023-29335HIGHCVSS 7.5fixed in 10.0.19042.29652023-05-09
CVE-2023-29335 [HIGH] CWE-20 CVE-2023-29335: Microsoft Word Security Feature Bypass Vulnerability Microsoft Word Security Feature Bypass Vulnerability
nvd
CVE-2023-24942HIGHCVSS 7.5fixed in 10.0.19042.29652023-05-09
CVE-2023-24942 [HIGH] CWE-126 CVE-2023-24942: Remote Procedure Call Runtime Denial of Service Vulnerability Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-24948HIGHCVSS 7.4fixed in 10.0.19042.29652023-05-09
CVE-2023-24948 [HIGH] CWE-122 CVE-2023-24948: Windows Bluetooth Driver Elevation of Privilege Vulnerability Windows Bluetooth Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-24901HIGHCVSS 7.5fixed in 10.0.19042.29652023-05-09
CVE-2023-24901 [HIGH] CWE-126 CVE-2023-24901: Windows NFS Portmapper Information Disclosure Vulnerability Windows NFS Portmapper Information Disclosure Vulnerability
nvd
CVE-2023-28251MEDIUMCVSS 5.5fixed in 10.0.19042.29652023-05-09
CVE-2023-28251 [MEDIUM] CVE-2023-28251: Windows Driver Revocation List Security Feature Bypass Vulnerability Windows Driver Revocation List Security Feature Bypass Vulnerability
nvd
CVE-2023-24954MEDIUMCVSS 6.5fixed in 10.0.19042.29652023-05-09
CVE-2023-24954 [MEDIUM] CWE-918 CVE-2023-24954: Microsoft SharePoint Server Information Disclosure Vulnerability Microsoft SharePoint Server Information Disclosure Vulnerability
nvd
CVE-2023-24944MEDIUMCVSS 6.5fixed in 10.0.19042.29652023-05-09
CVE-2023-24944 [MEDIUM] CWE-843 CVE-2023-24944: Windows Bluetooth Driver Information Disclosure Vulnerability Windows Bluetooth Driver Information Disclosure Vulnerability
nvd
CVE-2023-29324MEDIUMCVSS 6.5fixed in 10.0.19042.29652023-05-09
CVE-2023-29324 [MEDIUM] CWE-73 CVE-2023-29324: Windows MSHTML Platform Security Feature Bypass Vulnerability Windows MSHTML Platform Security Feature Bypass Vulnerability
nvd
CVE-2023-24945MEDIUMCVSS 5.5fixed in 10.0.19042.29652023-05-09
CVE-2023-24945 [MEDIUM] CWE-190 CVE-2023-24945: Windows iSCSI Target Service Information Disclosure Vulnerability Windows iSCSI Target Service Information Disclosure Vulnerability
nvd
CVE-2023-24900MEDIUMCVSS 5.9fixed in 10.0.19042.29652023-05-09
CVE-2023-24900 [MEDIUM] CWE-125 CVE-2023-24900: Windows NTLM Security Support Provider Information Disclosure Vulnerability Windows NTLM Security Support Provider Information Disclosure Vulnerability
nvd
CVE-2023-21712HIGHCVSS 8.1fixed in 10.0.19042.22512023-04-27
CVE-2023-21712 [HIGH] CWE-362 CVE-2023-21712: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-21554CRITICALCVSS 9.8PoCfixed in 10.0.19042.28462023-04-11
CVE-2023-21554 [CRITICAL] CWE-20 CVE-2023-21554: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2023-28250CRITICALCVSS 9.8fixed in 10.0.19042.28462023-04-11
CVE-2023-28250 [CRITICAL] CWE-191 CVE-2023-28250: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-28302HIGHCVSS 7.5fixed in 10.0.19042.28462023-04-11
CVE-2023-28302 [HIGH] CWE-20 CVE-2023-28302: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2023-28248HIGHCVSS 7.8fixed in 10.0.19042.28462023-04-11
CVE-2023-28248 [HIGH] CWE-190 CVE-2023-28248: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-28252HIGHCVSS 7.8KEVPoCfixed in 10.0.19042.28462023-04-11
CVE-2023-28252 [HIGH] CWE-122 CVE-2023-28252: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-28232HIGHCVSS 7.5fixed in 10.0.19042.28462023-04-11
CVE-2023-28232 [HIGH] CWE-362 CVE-2023-28232: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd