cbcvebase.

Microsoft Windows 10 Version 1607 vulnerabilities

3,019 known vulnerabilities affecting microsoft/windows_10_version_1607.

Total CVEs
3,019
CISA KEV
102
actively exploited
Public exploits
82
Exploited in wild
134
Severity breakdown
CRITICAL95HIGH2175MEDIUM737LOW12

Vulnerabilities

Page 58 of 151
CVE-2019-0909P3HIGHCVSS 7.5≥ 10.0.14393.0, < publication2019-06-12
CVE-2019-0909 [HIGH] CVE-2019-0909: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerabili
nvd
CVE-2025-48822P3HIGHCVSS 8.6≥ 10.0.14393.0, < 10.0.14393.82462025-07-08
CVE-2025-48822 [HIGH] CWE-125 CVE-2025-48822: Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50507P3MEDIUMCVSS 6.8≥ 10.0.14393.0, < 10.0.14393.92342026-06-09
CVE-2026-50507 [MEDIUM] CWE-306 CVE-2026-50507: Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2020-16939P3HIGHCVSS 7.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16939 [HIGH] CWE-59 CVE-2020-16939: <p>An elevation of privilege vulnerability exists when Group Policy improperly checks access. An att An elevation of privilege vulnerability exists when Group Policy improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted application to take control over the affecte
nvd
CVE-2022-35793P3HIGHCVSS 7.3≥ 10.0.14393.0, < 10.0.14393.52912022-08-09
CVE-2022-35793 [HIGH] CVE-2022-35793: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-26931P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-26931 [HIGH] CVE-2022-26931: Windows Kerberos Elevation of Privilege Vulnerability Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2024-38127P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38127 [HIGH] CWE-126 CVE-2024-38127: Windows Hyper-V Elevation of Privilege Vulnerability Windows Hyper-V Elevation of Privilege Vulnerability
nvd
CVE-2024-38062P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.71592024-07-09
CVE-2024-38062 [HIGH] CWE-125 CVE-2024-38062: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
nvd
CVE-2021-28315P3HIGHCVSS 7.8≥ 10.0.0, < publication2021-04-13
CVE-2021-28315 [HIGH] CVE-2021-28315: Windows Media Video Decoder Remote Code Execution Vulnerability Windows Media Video Decoder Remote Code Execution Vulnerability
nvd
CVE-2022-30209P3HIGHCVSS 7.4≥ 10.0.14393.0, < 10.0.14393.52462022-07-12
CVE-2022-30209 [HIGH] CVE-2022-30209: Windows IIS Server Elevation of Privilege Vulnerability Windows IIS Server Elevation of Privilege Vulnerability
nvd
CVE-2024-38245P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.73362024-09-10
CVE-2024-38245 [HIGH] CWE-20 CVE-2024-38245: Kernel Streaming Service Driver Elevation of Privilege Vulnerability Kernel Streaming Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-21363P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.67092024-02-13
CVE-2024-21363 [HIGH] CWE-843 CVE-2024-21363: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2026-20875P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.87832026-01-13
CVE-2026-20875 [HIGH] CWE-476 CVE-2026-20875: Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an una Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2024-38243P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.73362024-09-10
CVE-2024-38243 [HIGH] CWE-20 CVE-2024-38243: Kernel Streaming Service Driver Elevation of Privilege Vulnerability Kernel Streaming Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-38238P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.73362024-09-10
CVE-2024-38238 [HIGH] CWE-122 CVE-2024-38238: Kernel Streaming Service Driver Elevation of Privilege Vulnerability Kernel Streaming Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-20682P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.66142024-01-09
CVE-2024-20682 [HIGH] CWE-822 CVE-2024-20682: Windows Cryptographic Services Remote Code Execution Vulnerability Windows Cryptographic Services Remote Code Execution Vulnerability
nvd
CVE-2024-38057P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.71592024-07-09
CVE-2024-38057 [HIGH] CWE-125 CVE-2024-38057: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-33056P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.81482025-06-10
CVE-2025-33056 [HIGH] CWE-284 CVE-2025-33056: Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2024-38134P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38134 [HIGH] CWE-125 CVE-2024-38134: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-21375P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.77852025-02-11
CVE-2025-21375 [HIGH] CWE-20 CVE-2025-21375: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd