cbcvebase.

Microsoft Windows 10 Version 1607 vulnerabilities

3,019 known vulnerabilities affecting microsoft/windows_10_version_1607.

Total CVEs
3,019
CISA KEV
102
actively exploited
Public exploits
82
Exploited in wild
134
Severity breakdown
CRITICAL95HIGH2175MEDIUM737LOW12

Vulnerabilities

Page 110 of 151
CVE-2025-21301P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21301 [MEDIUM] CWE-284 CVE-2025-21301: Windows Geolocation Service Information Disclosure Vulnerability Windows Geolocation Service Information Disclosure Vulnerability
nvd
CVE-2023-24865P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.57862023-03-14
CVE-2023-24865 [MEDIUM] CWE-20 CVE-2023-24865: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-24866P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.57862023-03-14
CVE-2023-24866 [MEDIUM] CWE-20 CVE-2023-24866: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-35296P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-35296 [MEDIUM] CWE-125 CVE-2023-35296: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2026-26152P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.90602026-04-14
CVE-2026-26152 [HIGH] CWE-922 CVE-2026-26152: Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized att Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-27468P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.80662025-05-13
CVE-2025-27468 [HIGH] CWE-269 CVE-2025-27468: Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-41097P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.55012022-11-09
CVE-2022-41097 [MEDIUM] CVE-2022-41097: Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability
nvd
CVE-2023-35316P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-35316 [MEDIUM] CWE-125 CVE-2023-35316: Remote Procedure Call Runtime Information Disclosure Vulnerability Remote Procedure Call Runtime Information Disclosure Vulnerability
nvd
CVE-2023-36564P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.63512023-10-10
CVE-2023-36564 [MEDIUM] CVE-2023-36564: Windows Search Security Feature Bypass Vulnerability Windows Search Security Feature Bypass Vulnerability
nvd
CVE-2023-35332P4MEDIUMCVSS 6.8≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-35332 [MEDIUM] CWE-326 CVE-2023-35332: Windows Remote Desktop Protocol Security Feature Bypass Windows Remote Desktop Protocol Security Feature Bypass
nvd
CVE-2025-29958P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.80662025-05-13
CVE-2025-29958 [MEDIUM] CWE-908 CVE-2025-29958: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthor Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-29961P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.80662025-05-13
CVE-2025-29961 [MEDIUM] CWE-125 CVE-2025-29961: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2024-37976P4MEDIUMCVSS 6.7≥ 10.0.14393.0, < 10.0.14393.74282024-10-08
CVE-2024-37976 [MEDIUM] CWE-190 CVE-2024-37976: Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
nvd
CVE-2024-37983P4MEDIUMCVSS 6.7≥ 10.0.14393.0, < 10.0.14393.74282024-10-08
CVE-2024-37983 [MEDIUM] CWE-822 CVE-2024-37983: Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
nvd
CVE-2025-29836P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.80662025-05-13
CVE-2025-29836 [MEDIUM] CWE-125 CVE-2025-29836: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-49168P4MEDIUMCVSS 6.8≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-49168 [MEDIUM] CWE-190 CVE-2026-49168: Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to e Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2025-29830P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.80662025-05-13
CVE-2025-29830 [MEDIUM] CWE-908 CVE-2025-29830: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthor Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-54104P3MEDIUMCVSS 6.7≥ 10.0.14393.0, < 10.0.14393.84222025-09-09
CVE-2025-54104 [MEDIUM] CWE-843 CVE-2025-54104: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54915P3MEDIUMCVSS 6.7≥ 10.0.14393.0, < 10.0.14393.84222025-09-09
CVE-2025-54915 [MEDIUM] CWE-843 CVE-2025-54915: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54109P3MEDIUMCVSS 6.7≥ 10.0.14393.0, < 10.0.14393.84222025-09-09
CVE-2025-54109 [MEDIUM] CWE-843 CVE-2025-54109: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
nvd