Microsoft Windows 10 Version 1607 vulnerabilities
3,019 known vulnerabilities affecting microsoft/windows_10_version_1607.
Total CVEs
3,019
CISA KEV
102
actively exploited
Public exploits
82
Exploited in wild
133
Severity breakdown
CRITICAL95HIGH2175MEDIUM737LOW12
Vulnerabilities
Page 2 of 151
CVE-2025-26633P1HIGHCVSS 7.0KEVPoCRansomware≥ 10.0.14393.0, < 10.0.14393.78762025-03-11
CVE-2025-26633 [HIGH] CWE-707 CVE-2025-26633: Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
nvd
CVE-2021-41379P1HIGHCVSS 7.8KEVPoCRansomware≥ 10.0.0, < 10.0.14393.47702021-11-10
CVE-2021-41379 [HIGH] CWE-59 CVE-2021-41379: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2024-49138P1HIGHCVSS 7.8KEVPoC≥ 10.0.14393.0, < 10.0.14393.76062024-12-12
CVE-2024-49138 [HIGH] CWE-122 CVE-2024-49138: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-35250P1HIGHCVSS 7.8KEVPoC≥ 10.0.14393.0, < 10.0.14393.70702024-06-11
CVE-2024-35250 [HIGH] CWE-822 CVE-2024-35250: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-38193P1HIGHCVSS 7.8KEVPoC≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38193 [HIGH] CWE-416 CVE-2024-38193: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd
CVE-2022-24521P1HIGHCVSS 7.8KEVPoCRansomware≥ 10.0.14393.0, < 10.0.14393.50662022-04-15
CVE-2022-24521 [HIGH] CWE-787 CVE-2022-24521: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-29360P1HIGHCVSS 8.4KEVPoC≥ 10.0.14393.0, < 10.0.14393.59892023-06-14
CVE-2023-29360 [HIGH] CWE-822 CVE-2023-29360: Microsoft Streaming Service Elevation of Privilege Vulnerability
Microsoft Streaming Service Elevation of Privilege Vulnerability
nvd
CVE-2024-30051P1HIGHCVSS 7.8KEVPoCRansomware≥ 10.0.14393.0, < 10.0.14393.69812024-05-14
CVE-2024-30051 [HIGH] CWE-122 CVE-2024-30051: Windows DWM Core Library Elevation of Privilege Vulnerability
Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2021-34484P1HIGHCVSS 7.8KEVPoC≥ 10.0.0, < 10.0.14393.45832021-08-12
CVE-2021-34484 [HIGH] CVE-2021-34484: Windows User Profile Service Elevation of Privilege Vulnerability
Windows User Profile Service Elevation of Privilege Vulnerability
nvd
CVE-2021-36955P1HIGHCVSS 7.8KEVPoCRansomware≥ 10.0.0, < 10.0.14393.46512021-09-15
CVE-2021-36955 [HIGH] CVE-2021-36955: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2021-43226P1HIGHCVSS 7.8KEVPoCRansomware≥ 10.0.0, < 10.0.14393.48252021-12-15
CVE-2021-43226 [HIGH] CVE-2021-43226: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2026-32202P2MEDIUMCVSS 4.3KEVPoC≥ 10.0.14393.0, < 10.0.14393.90602026-04-14
CVE-2026-32202 [MEDIUM] CWE-693 CVE-2026-32202: Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing ov
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2019-1064P1HIGHCVSS 7.8KEVPoCRansomware≥ 10.0.14393.0, < publication2019-06-12
CVE-2019-1064 [HIGH] CWE-59 CVE-2019-1064: An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improp
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change or delete data.
To exploit this vulnerability, an attacker would first have
nvd
CVE-2023-36424P1HIGHCVSS 7.8KEVPoC≥ 10.0.14393.0, < 10.0.14393.64522023-11-14
CVE-2023-36424 [HIGH] CWE-125 CVE-2023-36424: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-24990P1HIGHCVSS 7.8KEVPoC≥ 10.0.14393.0, < 10.0.14393.85192025-10-14
CVE-2025-24990 [HIGH] CWE-822 CVE-2025-24990: Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with
Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update.
Fax modem hardware dependent on this specific driver will no longer work on Window
nvd
CVE-2022-26904P1HIGHCVSS 7.0KEVPoC≥ 10.0.14393.0, < 10.0.14393.50662022-04-15
CVE-2022-26904 [HIGH] CWE-362 CVE-2022-26904: Windows User Profile Service Elevation of Privilege Vulnerability
Windows User Profile Service Elevation of Privilege Vulnerability
nvd
CVE-2022-21919P1HIGHCVSS 7.0KEVPoC≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21919 [HIGH] CWE-59 CVE-2022-21919: Windows User Profile Service Elevation of Privilege Vulnerability
Windows User Profile Service Elevation of Privilege Vulnerability
nvd
CVE-2020-17087P1HIGHCVSS 7.8KEVPoC≥ 10.0.0, < publication2020-11-11
CVE-2020-17087 [HIGH] CWE-131 CVE-2020-17087: Windows Kernel Local Elevation of Privilege Vulnerability
Windows Kernel Local Elevation of Privilege Vulnerability
nvd
CVE-2023-28229P1HIGHCVSS 7.0KEVPoC≥ 10.0.14393.0, < 10.0.14393.58502023-04-11
CVE-2023-28229 [HIGH] CWE-591 CVE-2023-28229: Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
nvd
CVE-2026-20805P2MEDIUMCVSS 5.5KEVPoC≥ 10.0.14393.0, < 10.0.14393.87832026-01-13
CVE-2026-20805 [MEDIUM] CWE-200 CVE-2026-20805: Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an auth
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
nvd