Microsoft Windows 10 Version 1607 vulnerabilities
3,019 known vulnerabilities affecting microsoft/windows_10_version_1607.
Total CVEs
3,019
CISA KEV
102
actively exploited
Public exploits
82
Exploited in wild
134
Severity breakdown
CRITICAL95HIGH2175MEDIUM737LOW12
Vulnerabilities
Page 126 of 151
CVE-2026-50442P4MEDIUMCVSS 5.5≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50442 [MEDIUM] CWE-200 CVE-2026-50442: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50473P4MEDIUMCVSS 5.5≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50473 [MEDIUM] CWE-200 CVE-2026-50473: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50456P4MEDIUMCVSS 5.5≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50456 [MEDIUM] CWE-200 CVE-2026-50456: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-41087P4MEDIUMCVSS 5.5≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-41087 [MEDIUM] CWE-200 CVE-2026-41087: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32084P4MEDIUMCVSS 5.5≥ 10.0.14393.0, < 10.0.14393.90602026-04-14
CVE-2026-32084 [MEDIUM] CWE-200 CVE-2026-32084: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32079P4MEDIUMCVSS 5.5≥ 10.0.14393.0, < 10.0.14393.90602026-04-14
CVE-2026-32079 [MEDIUM] CWE-200 CVE-2026-32079: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50437P4MEDIUMCVSS 5.5≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50437 [MEDIUM] CWE-125 CVE-2026-50437: Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
nvd
CVE-2025-21247P4MEDIUMCVSS 4.3≥ 10.0.14393.0, < 10.0.14393.78762025-03-11
CVE-2025-21247 [MEDIUM] CWE-41 CVE-2025-21247: Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to b
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2021-24080P4MEDIUMCVSS 6.5≥ 10.0.0, < publication2021-02-25
CVE-2021-24080 [MEDIUM] CVE-2021-24080: Windows Trust Verification API Denial of Service Vulnerability
Windows Trust Verification API Denial of Service Vulnerability
nvd
CVE-2026-21249P4LOWCVSS 3.3≥ 10.0.14393.0, < 10.0.14393.88682026-02-10
CVE-2026-21249 [LOW] CWE-73 CVE-2026-21249: External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spo
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
nvd
CVE-2023-38254P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.61672023-08-08
CVE-2023-38254 [MEDIUM] CWE-20 CVE-2023-38254: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21272P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21272 [MEDIUM] CWE-908 CVE-2025-21272: Windows COM Server Information Disclosure Vulnerability
Windows COM Server Information Disclosure Vulnerability
nvd
CVE-2025-21288P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21288 [MEDIUM] CWE-908 CVE-2025-21288: Windows COM Server Information Disclosure Vulnerability
Windows COM Server Information Disclosure Vulnerability
nvd
CVE-2024-21344P4MEDIUMCVSS 5.9≥ 10.0.14393.0, < 10.0.14393.67092024-02-13
CVE-2024-21344 [MEDIUM] CWE-125 CVE-2024-21344: Windows Network Address Translation (NAT) Denial of Service Vulnerability
Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2022-35747P4MEDIUMCVSS 5.9≥ 10.0.14393.0, < 10.0.14393.52912023-05-31
CVE-2022-35747 [MEDIUM] CVE-2022-35747: Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
nvd
CVE-2024-38254P4MEDIUMCVSS 6.2≥ 10.0.14393.0, < 10.0.14393.73362024-09-10
CVE-2024-38254 [MEDIUM] CWE-908 CVE-2024-38254: Windows Authentication Information Disclosure Vulnerability
Windows Authentication Information Disclosure Vulnerability
nvd
CVE-2025-29957P4MEDIUMCVSS 6.2≥ 10.0.14393.0, < 10.0.14393.80662025-05-13
CVE-2025-29957 [MEDIUM] CWE-400 CVE-2025-29957: Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to
Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally.
nvd
CVE-2019-1143P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2019-08-14
CVE-2019-1143 [MEDIUM] CWE-200 CVE-2019-1143: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open
nvd
CVE-2019-1158P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2019-08-14
CVE-2019-1158 [MEDIUM] CWE-200 CVE-2019-1158: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open
nvd
CVE-2019-1163P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2019-08-14
CVE-2019-1163 [MEDIUM] CWE-354 CVE-2019-1163: A security feature bypass exists when Windows incorrectly validates CAB file signatures. An attacker
A security feature bypass exists when Windows incorrectly validates CAB file signatures. An attacker who successfully exploited this vulnerability could inject code into a CAB file without invalidating the file's signature.
To exploit the vulnerability, an attacker could modify a signed CAB file and inject malicious code. The attacker could then convi
nvd