Microsoft Windows 10 20H2 vulnerabilities
210 known vulnerabilities affecting microsoft/windows_10_20h2.
Total CVEs
210
CISA KEV
43
actively exploited
Public exploits
25
Exploited in wild
45
Severity breakdown
CRITICAL11HIGH156MEDIUM43
Vulnerabilities
Page 6 of 11
CVE-2022-35745P3HIGHCVSS 8.1fixed in 10.0.19042.18892023-05-31
CVE-2022-35745 [HIGH] CVE-2022-35745: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2022-35752P3HIGHCVSS 8.1fixed in 10.0.19042.18892023-05-31
CVE-2022-35752 [HIGH] CVE-2022-35752: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2022-35753P3HIGHCVSS 8.1fixed in 10.0.19042.18892023-05-31
CVE-2022-35753 [HIGH] CVE-2022-35753: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2023-23405P3HIGHCVSS 8.1fixed in 10.0.19042.27282023-03-14
CVE-2023-23405 [HIGH] CWE-190 CVE-2023-23405: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2023-24908P3HIGHCVSS 8.1fixed in 10.0.19042.27282023-03-14
CVE-2023-24908 [HIGH] CWE-190 CVE-2023-24908: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2023-24869P3HIGHCVSS 8.1fixed in 10.0.19042.27282023-03-14
CVE-2023-24869 [HIGH] CWE-190 CVE-2023-24869: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2023-21712P3HIGHCVSS 8.1fixed in 10.0.19042.22512023-04-27
CVE-2023-21712 [HIGH] CWE-362 CVE-2023-21712: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-24903P3HIGHCVSS 8.1fixed in 10.0.19042.29652023-05-09
CVE-2023-24903 [HIGH] CWE-415 CVE-2023-24903: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2023-23404P3HIGHCVSS 8.1fixed in 10.0.19042.27282023-03-14
CVE-2023-23404 [HIGH] CWE-416 CVE-2023-23404: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2022-35756P3HIGHCVSS 7.8fixed in 10.0.19042.18892023-05-31
CVE-2022-35756 [HIGH] CVE-2022-35756: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2023-28274P3HIGHCVSS 7.8fixed in 10.0.19042.28462023-04-11
CVE-2023-28274 [HIGH] CWE-20 CVE-2023-28274: Windows Win32k Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
nvd
CVE-2023-23388P3HIGHCVSS 8.8fixed in 10.0.19042.27282023-03-14
CVE-2023-23388 [HIGH] CWE-681 CVE-2023-23388: Windows Bluetooth Driver Elevation of Privilege Vulnerability
Windows Bluetooth Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-23410P3HIGHCVSS 7.8fixed in 10.0.19042.27282023-03-14
CVE-2023-23410 [HIGH] CWE-190 CVE-2023-23410: Windows HTTP.sys Elevation of Privilege Vulnerability
Windows HTTP.sys Elevation of Privilege Vulnerability
nvd
CVE-2023-28238P3HIGHCVSS 7.5fixed in 10.0.19042.28462023-04-11
CVE-2023-28238 [HIGH] CWE-591 CVE-2023-28238: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2022-35751P3HIGHCVSS 7.8fixed in 10.0.19042.18892023-05-31
CVE-2022-35751 [HIGH] CVE-2022-35751: Windows Hyper-V Elevation of Privilege Vulnerability
Windows Hyper-V Elevation of Privilege Vulnerability
nvd
CVE-2023-21812P3HIGHCVSS 7.8fixed in 10.0.19042.26042023-02-14
CVE-2023-21812 [HIGH] CWE-122 CVE-2023-21812: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-35755P3HIGHCVSS 7.3fixed in 10.0.19042.18892023-05-31
CVE-2022-35755 [HIGH] CVE-2022-35755: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2023-1017P3HIGHCVSS 7.8fixed in 10.0.19042.27282023-02-28
CVE-2023-1017 [HIGH] CWE-787 CVE-2023-1017: An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte
An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of service (crashing the TPM chip/process or rendering it unusable) and/or arbitrary code execution
nvd
CVE-2023-24912P3HIGHCVSS 7.8fixed in 10.0.19042.28462023-04-11
CVE-2023-24912 [HIGH] CWE-122 CVE-2023-24912: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2023-28232P3HIGHCVSS 7.5fixed in 10.0.19042.28462023-04-11
CVE-2023-28232 [HIGH] CWE-362 CVE-2023-28232: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd