Microsoft Windows 10 Version 1607 vulnerabilities
3,019 known vulnerabilities affecting microsoft/windows_10_version_1607.
Total CVEs
3,019
CISA KEV
102
actively exploited
Public exploits
82
Exploited in wild
134
Severity breakdown
CRITICAL95HIGH2175MEDIUM737LOW12
Vulnerabilities
Page 128 of 151
CVE-2025-21219P4MEDIUMCVSS 4.3≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21219 [MEDIUM] CWE-41 CVE-2025-21219: MapUrlToZone Security Feature Bypass Vulnerability
MapUrlToZone Security Feature Bypass Vulnerability
nvd
CVE-2025-21189P4MEDIUMCVSS 4.3≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21189 [MEDIUM] CWE-41 CVE-2025-21189: MapUrlToZone Security Feature Bypass Vulnerability
MapUrlToZone Security Feature Bypass Vulnerability
nvd
CVE-2025-55333P4MEDIUMCVSS 4.6≥ 10.0.14393.0, < 10.0.14393.85192025-10-14
CVE-2025-55333 [MEDIUM] CWE-1023 CVE-2025-55333: Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to b
Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2026-50661P4MEDIUMCVSS 4.6≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50661 [MEDIUM] CWE-693 CVE-2026-50661: Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a securi
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2022-34728P4MEDIUMCVSS 5.5≥ 10.0.14393.0, < 10.0.14393.53562022-09-13
CVE-2022-34728 [MEDIUM] CVE-2022-34728: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2022-26935P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-26935 [MEDIUM] CVE-2022-26935: Windows WLAN AutoConfig Service Information Disclosure Vulnerability
Windows WLAN AutoConfig Service Information Disclosure Vulnerability
nvd
CVE-2023-36908P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.61672023-08-08
CVE-2023-36908 [MEDIUM] CWE-200 CVE-2023-36908: Windows Hyper-V Information Disclosure Vulnerability
Windows Hyper-V Information Disclosure Vulnerability
nvd
CVE-2021-1656P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2021-01-12
CVE-2021-1656 [MEDIUM] CVE-2021-1656: TPM Device Driver Information Disclosure Vulnerability
TPM Device Driver Information Disclosure Vulnerability
nvd
CVE-2019-1078P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2019-08-14
CVE-2019-1078 [MEDIUM] CWE-200 CVE-2019-1078: An information disclosure vulnerability exists when the Windows Graphics component improperly handle
An information disclosure vulnerability exists when the Windows Graphics component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
An authenticated attacker could exploit this vulnerability by running a specially crafted application.
The u
nvd
CVE-2020-1474P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-08-17
CVE-2020-1474 [MEDIUM] CVE-2020-1474: An information disclosure vulnerability exists when the Windows Image Acquisition (WIA) Service impr
An information disclosure vulnerability exists when the Windows Image Acquisition (WIA) Service improperly discloses contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit the vulnerability, an authenticated attacker could connect an imaging device (camera,
nvd
CVE-2019-1039P4MEDIUMCVSS 5.5≥ 10.0.14393.0, < publication2019-06-12
CVE-2019-1039 [MEDIUM] CWE-665 CVE-2019-1039: An information disclosure vulnerability exists when the Windows kernel improperly initializes object
An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.
To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
The update addre
nvd
CVE-2019-1172P4MEDIUMCVSS 4.3≥ 10.0.0, < publication2019-08-14
CVE-2019-1172 [MEDIUM] CWE-200 CVE-2019-1172: An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MS
An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login request session. An attacker who successfully exploited the vulnerability could take over a user's account.
To exploit the vulnerability, an attacker would have to trick a user into browsing to a specially crafted website, allowing t
nvd
CVE-2025-24992P4MEDIUMCVSS 5.5≥ 10.0.14393.0, < 10.0.14393.78762025-03-11
CVE-2025-24992 [MEDIUM] CWE-126 CVE-2025-24992: Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.
nvd
CVE-2023-21682P4MEDIUMCVSS 5.3≥ 10.0.14393.0, < 10.0.14393.56482023-01-10
CVE-2023-21682 [MEDIUM] CWE-125 CVE-2023-21682: Windows Point-to-Point Protocol (PPP) Information Disclosure Vulnerability
Windows Point-to-Point Protocol (PPP) Information Disclosure Vulnerability
nvd
CVE-2024-38256P4MEDIUMCVSS 5.5≥ 10.0.14393.0, < 10.0.14393.73362024-09-10
CVE-2024-38256 [MEDIUM] CWE-908 CVE-2024-38256: Windows Kernel-Mode Driver Information Disclosure Vulnerability
Windows Kernel-Mode Driver Information Disclosure Vulnerability
nvd
CVE-2024-43554P4MEDIUMCVSS 5.5≥ 10.0.14393.0, < 10.0.14393.74282024-10-08
CVE-2024-43554 [MEDIUM] CWE-212 CVE-2024-43554: Windows Kernel-Mode Driver Information Disclosure Vulnerability
Windows Kernel-Mode Driver Information Disclosure Vulnerability
nvd
CVE-2023-21699P4MEDIUMCVSS 5.3≥ 10.0.14393.0, < 10.0.14393.57172023-02-14
CVE-2023-21699 [MEDIUM] CWE-125 CVE-2023-21699: Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability
Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability
nvd
CVE-2025-33055P4MEDIUMCVSS 5.5≥ 10.0.14393.0, < 10.0.14393.81482025-06-10
CVE-2025-33055 [MEDIUM] CWE-125 CVE-2025-33055: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-33062P4MEDIUMCVSS 5.5≥ 10.0.14393.0, < 10.0.14393.81482025-06-10
CVE-2025-33062 [MEDIUM] CWE-125 CVE-2025-33062: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-33061P4MEDIUMCVSS 5.5≥ 10.0.14393.0, < 10.0.14393.81482025-06-10
CVE-2025-33061 [MEDIUM] CWE-125 CVE-2025-33061: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd