Microsoft Windows 10 Version 1507 vulnerabilities

2,277 known vulnerabilities affecting microsoft/windows_10_version_1507.

Total CVEs
2,277
CISA KEV
89
actively exploited
Public exploits
37
Exploited in wild
82
Severity breakdown
CRITICAL69HIGH1630MEDIUM570LOW8

Vulnerabilities

Page 8 of 114
CVE-2025-47973HIGHCVSS 7.8≥ 10.0.10240.0, < 10.0.10240.210732025-07-08
CVE-2025-47973 [HIGH] CWE-126 CVE-2025-47973: Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges l Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-49683HIGHCVSS 7.8PoC≥ 10.0.10240.0, < 10.0.10240.210732025-07-08
CVE-2025-49683 [HIGH] CWE-122 CVE-2025-49683: Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execut Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally.
cvelistv5nvd
CVE-2025-49675HIGHCVSS 7.8≥ 10.0.10240.0, < 10.0.10240.210732025-07-08
CVE-2025-49675 [HIGH] CWE-416 CVE-2025-49675: Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-49665HIGHCVSS 7.8≥ 10.0.10240.0, < 10.0.10240.210732025-07-08
CVE-2025-49665 [HIGH] CWE-362 CVE-2025-49665: Concurrent execution using shared resource with improper synchronization ('race condition') in Works Concurrent execution using shared resource with improper synchronization ('race condition') in Workspace Broker allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-49721HIGHCVSS 7.8≥ 10.0.10240.0, < 10.0.10240.210732025-07-08
CVE-2025-49721 [HIGH] CWE-122 CVE-2025-49721: Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate pri Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-47984HIGHCVSS 7.5≥ 10.0.10240.0, < 10.0.10240.210732025-07-08
CVE-2025-47984 [HIGH] CWE-693 CVE-2025-47984: Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network.
cvelistv5nvd
CVE-2025-49742HIGHCVSS 7.8≥ 10.0.10240.0, < 10.0.10240.210732025-07-08
CVE-2025-49742 [HIGH] CWE-122 CVE-2025-49742: Integer overflow or wraparound in Microsoft Graphics Component allows an authorized attacker to exec Integer overflow or wraparound in Microsoft Graphics Component allows an authorized attacker to execute code locally.
cvelistv5nvd
CVE-2025-49686HIGHCVSS 7.8≥ 10.0.10240.0, < 10.0.10240.210732025-07-08
CVE-2025-49686 [HIGH] CWE-476 CVE-2025-49686: Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges local Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-47972HIGHCVSS 8.0≥ 10.0.10240.0, < 10.0.10240.210732025-07-08
CVE-2025-47972 [HIGH] CWE-362 CVE-2025-47972: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges over a network.
cvelistv5nvd
CVE-2025-48805HIGHCVSS 7.8≥ 10.0.10240.0, < 10.0.10240.210732025-07-08
CVE-2025-48805 [HIGH] CWE-122 CVE-2025-48805: Heap-based buffer overflow in Microsoft MPEG-2 Video Extension allows an authorized attacker to exec Heap-based buffer overflow in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally.
cvelistv5nvd
CVE-2025-49687HIGHCVSS 8.8≥ 10.0.10240.0, < 10.0.10240.210732025-07-08
CVE-2025-49687 [HIGH] CWE-125 CVE-2025-49687: Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate p Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-49680HIGHCVSS 7.3≥ 10.0.10240.0, < 10.0.10240.210732025-07-08
CVE-2025-49680 [HIGH] CWE-59 CVE-2025-49680: Improper link resolution before file access ('link following') in Windows Performance Recorder allow Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized attacker to deny service locally.
cvelistv5nvd
CVE-2025-47986HIGHCVSS 8.8≥ 10.0.10240.0, < 10.0.10240.210732025-07-08
CVE-2025-47986 [HIGH] CWE-416 CVE-2025-47986: Use after free in Universal Print Management Service allows an authorized attacker to elevate privil Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-49678HIGHCVSS 7.0≥ 10.0.10240.0, < 10.0.10240.210732025-07-08
CVE-2025-49678 [HIGH] CWE-362 CVE-2025-49678: Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-48815HIGHCVSS 7.8≥ 10.0.10240.0, < 10.0.10240.210732025-07-08
CVE-2025-48815 [HIGH] CWE-843 CVE-2025-48815: Access of resource using incompatible type ('type confusion') in Windows SSDP Service allows an auth Access of resource using incompatible type ('type confusion') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-49679HIGHCVSS 7.8≥ 10.0.10240.0, < 10.0.10240.210732025-07-08
CVE-2025-49679 [HIGH] CWE-197 CVE-2025-49679: Numeric truncation error in Windows Shell allows an authorized attacker to elevate privileges locall Numeric truncation error in Windows Shell allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-49661HIGHCVSS 7.8≥ 10.0.10240.0, < 10.0.10240.210732025-07-08
CVE-2025-49661 [HIGH] CWE-822 CVE-2025-49661: Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-47996HIGHCVSS 7.8≥ 10.0.10240.0, < 10.0.10240.210732025-07-08
CVE-2025-47996 [HIGH] CWE-125 CVE-2025-47996: Integer underflow (wrap or wraparound) in Windows MBT Transport driver allows an authorized attacker Integer underflow (wrap or wraparound) in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-49667HIGHCVSS 7.8≥ 10.0.10240.0, < 10.0.10240.210732025-07-08
CVE-2025-49667 [HIGH] CWE-415 CVE-2025-49667: Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-47971HIGHCVSS 7.8≥ 10.0.10240.0, < 10.0.10240.210732025-07-08
CVE-2025-47971 [HIGH] CWE-126 CVE-2025-47971: Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges l Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
cvelistv5nvd
Microsoft Windows 10 Version 1507 vulnerabilities | cvebase