cbcvebase.

Microsoft Windows 10 Version 1607 vulnerabilities

3,019 known vulnerabilities affecting microsoft/windows_10_version_1607.

Total CVEs
3,019
CISA KEV
102
actively exploited
Public exploits
82
Exploited in wild
133
Severity breakdown
CRITICAL95HIGH2175MEDIUM737LOW12

Vulnerabilities

Page 27 of 151
CVE-2025-29966P3HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.80662025-05-13
CVE-2025-29966 [HIGH] CWE-122 CVE-2025-29966: Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21417P3HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21417 [HIGH] CWE-122 CVE-2025-21417: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21409P3HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21409 [HIGH] CWE-122 CVE-2025-21409: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21339P3HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21339 [HIGH] CWE-122 CVE-2025-21339: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21411P3HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21411 [HIGH] CWE-122 CVE-2025-21411: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21413P3HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21413 [HIGH] CWE-122 CVE-2025-21413: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-48817P3HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.82462025-07-08
CVE-2025-48817 [HIGH] CWE-23 CVE-2025-48817: Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code ove Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-20820P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.87832026-01-13
CVE-2026-20820 [HIGH] CWE-122 CVE-2026-20820: Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54916P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.84222025-09-09
CVE-2025-54916 [HIGH] CWE-121 CVE-2025-54916: Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2026-20856P3HIGHCVSS 8.1≥ 10.0.14393.0, < 10.0.14393.87832026-01-13
CVE-2026-20856 [HIGH] CWE-20 CVE-2026-20856: Improper input validation in Windows Server Update Service allows an unauthorized attacker to execut Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21277P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21277 [HIGH] CWE-126 CVE-2025-21277: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2022-30165P3HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.51922022-06-15
CVE-2022-30165 [HIGH] CVE-2022-30165: Windows Kerberos Elevation of Privilege Vulnerability Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2023-21818P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.57172023-02-14
CVE-2023-21818 [HIGH] CWE-20 CVE-2023-21818: Windows Secure Channel Denial of Service Vulnerability Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2026-20921P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.87832026-01-13
CVE-2026-20921 [HIGH] CWE-362 CVE-2026-20921: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2025-58726P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.85192025-10-14
CVE-2025-58726 [HIGH] CWE-284 CVE-2025-58726: Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges ov Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-20926P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.87832026-01-13
CVE-2026-20926 [HIGH] CWE-362 CVE-2026-20926: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-20919P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.87832026-01-13
CVE-2026-20919 [HIGH] CWE-362 CVE-2026-20919: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-20934P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.87832026-01-13
CVE-2026-20934 [HIGH] CWE-362 CVE-2026-20934: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-58531P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-58531 [HIGH] CWE-362 CVE-2026-58531: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2021-24091P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-02-25
CVE-2021-24091 [HIGH] CWE-787 CVE-2021-24091: Windows Camera Codec Pack Remote Code Execution Vulnerability Windows Camera Codec Pack Remote Code Execution Vulnerability
nvd
Microsoft Windows 10 Version 1607 vulnerabilities | cvebase