cbcvebase.

Microsoft Windows 10 Version 1607 vulnerabilities

3,019 known vulnerabilities affecting microsoft/windows_10_version_1607.

Total CVEs
3,019
CISA KEV
102
actively exploited
Public exploits
82
Exploited in wild
134
Severity breakdown
CRITICAL95HIGH2175MEDIUM737LOW12

Vulnerabilities

Page 84 of 151
CVE-2026-25171P3HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.89572026-03-10
CVE-2026-25171 [HIGH] CWE-416 CVE-2026-25171: Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32087P3HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.90602026-04-14
CVE-2026-32087 [HIGH] CWE-122 CVE-2026-32087: Heap-based buffer overflow in Function Discovery Service (fdwsd.dll) allows an authorized attacker t Heap-based buffer overflow in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50166P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.83302025-08-12
CVE-2025-50166 [MEDIUM] CWE-190 CVE-2025-50166: Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized a Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized attacker to disclose information over a network.
nvd
CVE-2024-30084P3HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.70702024-06-11
CVE-2024-30084 [HIGH] CWE-367 CVE-2024-30084: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-62473P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.86882025-12-09
CVE-2025-62473 [MEDIUM] CWE-126 CVE-2025-62473: Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2021-1734P3HIGHCVSS 7.5≥ 10.0.0, < publication2021-02-25
CVE-2021-1734 [HIGH] CVE-2021-1734: Windows Remote Procedure Call Information Disclosure Vulnerability Windows Remote Procedure Call Information Disclosure Vulnerability
nvd
CVE-2020-1534P3HIGHCVSS 7.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1534 [HIGH] CVE-2020-1534: An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles fi An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correcting how
nvd
CVE-2020-1478P3HIGHCVSS 7.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1478 [HIGH] CWE-787 CVE-2020-1478: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincin
nvd
CVE-2020-1477P3HIGHCVSS 7.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1477 [HIGH] CWE-787 CVE-2020-1477: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincin
nvd
CVE-2025-29809P3HIGHCVSS 7.1≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-29809 [HIGH] CWE-922 CVE-2025-29809: Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypas Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2021-40476P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.14393.47042021-10-13
CVE-2021-40476 [HIGH] CWE-522 CVE-2021-40476: Windows AppContainer Elevation Of Privilege Vulnerability Windows AppContainer Elevation Of Privilege Vulnerability
nvd
CVE-2021-43236P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.14393.48252021-12-15
CVE-2021-43236 [HIGH] CVE-2021-43236: Microsoft Message Queuing Information Disclosure Vulnerability Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2021-43222P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.14393.48252021-12-15
CVE-2021-43222 [HIGH] CVE-2021-43222: Microsoft Message Queuing Information Disclosure Vulnerability Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2024-21438P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.67962024-03-12
CVE-2024-21438 [HIGH] CWE-369 CVE-2024-21438: Microsoft AllJoyn API Denial of Service Vulnerability Microsoft AllJoyn API Denial of Service Vulnerability
nvd
CVE-2023-36709P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.63512023-10-10
CVE-2023-36709 [HIGH] CWE-476 CVE-2023-36709: Microsoft AllJoyn API Denial of Service Vulnerability Microsoft AllJoyn API Denial of Service Vulnerability
nvd
CVE-2024-38068P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.71592024-07-09
CVE-2024-38068 [HIGH] CWE-400 CVE-2024-38068: Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
nvd
CVE-2024-20687P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.66142024-01-09
CVE-2024-20687 [HIGH] CWE-125 CVE-2024-20687: Microsoft AllJoyn API Denial of Service Vulnerability Microsoft AllJoyn API Denial of Service Vulnerability
nvd
CVE-2025-21351P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.77852025-02-11
CVE-2025-21351 [HIGH] CWE-400 CVE-2025-21351: Windows Active Directory Domain Services API Denial of Service Vulnerability Windows Active Directory Domain Services API Denial of Service Vulnerability
nvd
CVE-2024-49121P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.76062024-12-12
CVE-2024-49121 [HIGH] CWE-476 CVE-2024-49121: Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
nvd
CVE-2023-36003P3HIGHCVSS 7.3≥ 10.0.14393.0, < 10.0.14393.65292023-12-12
CVE-2023-36003 [HIGH] CWE-426 CVE-2023-36003: XAML Diagnostics Elevation of Privilege Vulnerability XAML Diagnostics Elevation of Privilege Vulnerability
nvd