Microsoft Windows 10 Version 1507 vulnerabilities
2,277 known vulnerabilities affecting microsoft/windows_10_version_1507.
Total CVEs
2,277
CISA KEV
89
actively exploited
Public exploits
75
Exploited in wild
118
Severity breakdown
CRITICAL69HIGH1630MEDIUM570LOW8
Vulnerabilities
Page 6 of 114
CVE-2020-16896P1HIGHCVSS 7.5ExploitedRansomware≥ 10.0.0, < publication2020-10-16
CVE-2020-16896 [HIGH] CVE-2020-16896: <p>An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker
An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would need to run a
nvd
CVE-2021-43207P1HIGHCVSS 7.8ExploitedRansomware≥ 10.0.0, < 10.0.10240.191452021-12-15
CVE-2021-43207 [HIGH] CVE-2021-43207: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-35803P2HIGHCVSS 7.8Exploited≥ 10.0.10240.0, < 10.0.10240.194442022-09-13
CVE-2022-35803 [HIGH] CVE-2022-35803: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-38196P2HIGHCVSS 7.8Exploited≥ 10.0.10240.0, < 10.0.10240.207512024-08-13
CVE-2024-38196 [HIGH] CWE-20 CVE-2024-38196: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-21554P1CRITICALCVSS 9.8PoC≥ 10.0.10240.0, < 10.0.10240.198692023-04-11
CVE-2023-21554 [CRITICAL] CWE-20 CVE-2023-21554: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2025-24061P2HIGHCVSS 7.8Exploited≥ 10.0.10240.0, < 10.0.10240.209472025-03-11
CVE-2025-24061 [HIGH] CWE-693 CVE-2025-24061: Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to by
Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally.
nvd
CVE-2023-29324P2MEDIUMCVSS 6.5Exploited≥ 10.0.10240.0, < 10.0.10240.199262023-05-09
CVE-2023-29324 [MEDIUM] CWE-73 CVE-2023-29324: Windows MSHTML Platform Security Feature Bypass Vulnerability
Windows MSHTML Platform Security Feature Bypass Vulnerability
nvd
CVE-2023-28218P2HIGHCVSS 7.0Exploited≥ 10.0.10240.0, < 10.0.10240.198692023-04-11
CVE-2023-28218 [HIGH] CWE-122 CVE-2023-28218: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd
CVE-2021-26885P2HIGHCVSS 7.8Exploited≥ 10.0.0, < publication2021-03-11
CVE-2021-26885 [HIGH] CVE-2021-26885: Windows WalletService Elevation of Privilege Vulnerability
Windows WalletService Elevation of Privilege Vulnerability
nvd
CVE-2022-30170P2HIGHCVSS 7.3Exploited≥ 10.0.10240.0, < 10.0.10240.194442022-09-13
CVE-2022-30170 [HIGH] CVE-2022-30170: Windows Credential Roaming Service Elevation of Privilege Vulnerability
Windows Credential Roaming Service Elevation of Privilege Vulnerability
nvd
CVE-2024-38063P1CRITICALCVSS 9.8PoC≥ 10.0.10240.0, < 10.0.10240.207512024-08-13
CVE-2024-38063 [CRITICAL] CWE-191 CVE-2024-38063: Windows TCP/IP Remote Code Execution Vulnerability
Windows TCP/IP Remote Code Execution Vulnerability
nvd
CVE-2022-21874P2CRITICALCVSS 9.8Exploited≥ 10.0.10240.0, < 10.0.10240.191772022-01-11
CVE-2022-21874 [CRITICAL] CVE-2022-21874: Windows Security Center API Remote Code Execution Vulnerability
Windows Security Center API Remote Code Execution Vulnerability
nvd
CVE-2019-1150P2HIGHCVSS 8.8PoC≥ 10.0.0, < publication2019-08-14
CVE-2019-1150 [HIGH] CWE-787 CVE-2019-1150: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whos
nvd
CVE-2025-21293P2HIGHCVSS 8.8PoC≥ 10.0.10240.0, < 10.0.10240.208902025-01-14
CVE-2025-21293 [HIGH] CWE-284 CVE-2025-21293: Active Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2019-1151P2HIGHCVSS 8.8PoC≥ 10.0.0, < publication2019-08-14
CVE-2019-1151 [HIGH] CWE-787 CVE-2019-1151: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whos
nvd
CVE-2024-49112P1CRITICALCVSS 9.8≥ 10.0.10240.0, < 10.0.10240.208572024-12-12
CVE-2024-49112 [CRITICAL] CWE-190 CVE-2024-49112: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2019-1181P2CRITICALCVSS 9.8≥ 10.0.0, < publication2019-08-14
CVE-2019-1181 [CRITICAL] CVE-2019-1181: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability cou
nvd
CVE-2019-1149P2HIGHCVSS 8.8PoC≥ 10.0.0, < publication2019-08-14
CVE-2019-1149 [HIGH] CWE-787 CVE-2019-1149: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whos
nvd
CVE-2019-1144P2HIGHCVSS 8.8PoC≥ 10.0.0, < publication2019-08-14
CVE-2019-1144 [HIGH] CWE-415 CVE-2019-1144: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whos
nvd
CVE-2019-1152P2HIGHCVSS 8.8PoC≥ 10.0.0, < publication2019-08-14
CVE-2019-1152 [HIGH] CWE-787 CVE-2019-1152: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whos
nvd