Microsoft Windows 10 Version 1607 vulnerabilities
3,019 known vulnerabilities affecting microsoft/windows_10_version_1607.
Total CVEs
3,019
CISA KEV
102
actively exploited
Public exploits
82
Exploited in wild
133
Severity breakdown
CRITICAL95HIGH2175MEDIUM737LOW12
Vulnerabilities
Page 21 of 151
CVE-2025-58722P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.85192025-10-14
CVE-2025-58722 [HIGH] CWE-122 CVE-2025-58722: Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locall
Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20860P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.87832026-01-13
CVE-2026-20860 [HIGH] CWE-843 CVE-2026-20860: Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver f
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56188P3HIGHCVSS 8.1≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-56188 [HIGH] CWE-362 CVE-2026-56188: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.
nvd
CVE-2019-0888P3HIGHCVSS 8.8≥ 10.0.14393.0, < publication2019-06-12
CVE-2019-0888 [HIGH] CVE-2019-0888: A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objec
A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with the victim user’s privileges.
An attacker could craft a website that exploits the vulnerability and then convince a victim user to visit the website.
The secu
nvd
CVE-2025-47984P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.82462025-07-08
CVE-2025-47984 [HIGH] CWE-693 CVE-2025-47984: Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information
Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-50686P3HIGHCVSS 8.1≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50686 [HIGH] CWE-843 CVE-2026-50686: Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized
Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-62452P3HIGHCVSS 8.0≥ 10.0.14393.0, < 10.0.14393.85942025-11-11
CVE-2025-62452 [HIGH] CWE-122 CVE-2025-62452: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
nvd
CVE-2025-60715P3HIGHCVSS 8.0≥ 10.0.14393.0, < 10.0.14393.85942025-11-11
CVE-2025-60715 [HIGH] CWE-122 CVE-2025-60715: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
nvd
CVE-2020-17042P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-11-11
CVE-2020-17042 [HIGH] CVE-2020-17042: Windows Print Spooler Remote Code Execution Vulnerability
Windows Print Spooler Remote Code Execution Vulnerability
nvd
CVE-2023-36434P3CRITICALCVSS 9.8≥ 10.0.14393.0, < 10.0.14393.63512023-10-10
CVE-2023-36434 [CRITICAL] CWE-307 CVE-2023-36434: Windows IIS Server Elevation of Privilege Vulnerability
Windows IIS Server Elevation of Privilege Vulnerability
nvd
CVE-2026-42980P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.92342026-06-09
CVE-2026-42980 [HIGH] CWE-122 CVE-2026-42980: Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elev
Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2020-16911P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16911 [HIGH] CVE-2020-16911: <p>A remote code execution vulnerability exists in the way that the Windows Graphics Device Interfac
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users w
nvd
CVE-2021-1674P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-01-12
CVE-2021-1674 [HIGH] CVE-2021-1674: Windows Remote Desktop Protocol Core Security Feature Bypass Vulnerability
Windows Remote Desktop Protocol Core Security Feature Bypass Vulnerability
nvd
CVE-2021-1669P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-01-12
CVE-2021-1669 [HIGH] CVE-2021-1669: Windows Remote Desktop Security Feature Bypass Vulnerability
Windows Remote Desktop Security Feature Bypass Vulnerability
nvd
CVE-2022-21922P3HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21922 [HIGH] CVE-2022-21922: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28327P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-04-13
CVE-2021-28327 [HIGH] CVE-2021-28327: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28340P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-04-13
CVE-2021-28340 [HIGH] CVE-2021-28340: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28356P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-04-13
CVE-2021-28356 [HIGH] CVE-2021-28356: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28344P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-04-13
CVE-2021-28344 [HIGH] CVE-2021-28344: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28333P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-04-13
CVE-2021-28333 [HIGH] CVE-2021-28333: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd