Microsoft Windows 10 Version 1607 vulnerabilities
3,019 known vulnerabilities affecting microsoft/windows_10_version_1607.
Total CVEs
3,019
CISA KEV
102
actively exploited
Public exploits
82
Exploited in wild
134
Severity breakdown
CRITICAL95HIGH2175MEDIUM737LOW12
Vulnerabilities
Page 95 of 151
CVE-2026-50397P3HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50397 [HIGH] CWE-416 CVE-2026-50397: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2020-1577P3MEDIUMCVSS 6.5≥ 10.0.0, < publication2020-08-17
CVE-2020-1577 [MEDIUM] CVE-2020-1577: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted
nvd
CVE-2025-59185P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.85192025-10-14
CVE-2025-59185 [MEDIUM] CWE-73 CVE-2025-59185: External control of file name or path in Windows Core Shell allows an unauthorized attacker to perfo
External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-56186P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-56186 [MEDIUM] CWE-125 CVE-2026-56186: Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a
Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-50376P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50376 [MEDIUM] CWE-908 CVE-2026-50376: Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-59244P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.85192025-10-14
CVE-2025-59244 [MEDIUM] CWE-73 CVE-2025-59244: External control of file name or path in Windows Core Shell allows an unauthorized attacker to perfo
External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-32151P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.90602026-04-14
CVE-2026-32151 [MEDIUM] CWE-200 CVE-2026-32151: Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized att
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-50432P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50432 [MEDIUM] CWE-416 CVE-2026-50432: Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny ser
Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.
nvd
CVE-2024-21433P3HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.67962024-03-12
CVE-2024-21433 [HIGH] CWE-367 CVE-2024-21433: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2025-21181P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.77852025-02-11
CVE-2025-21181 [HIGH] CWE-400 CVE-2025-21181: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2020-1552P3HIGHCVSS 7.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1552 [HIGH] CVE-2020-1552: An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handl
An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
An attacker could exploit this vulnerability by running a specially crafted application on the victim system.
The update addresses the vulner
nvd
CVE-2024-38126P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38126 [HIGH] CWE-476 CVE-2024-38126: Windows Network Address Translation (NAT) Denial of Service Vulnerability
Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2025-21300P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21300 [HIGH] CWE-400 CVE-2025-21300: Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability
Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability
nvd
CVE-2024-38145P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38145 [HIGH] CWE-476 CVE-2024-38145: Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
nvd
CVE-2024-38146P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38146 [HIGH] CWE-476 CVE-2024-38146: Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
nvd
CVE-2024-21348P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.67092024-02-13
CVE-2024-21348 [HIGH] CWE-122 CVE-2024-21348: Internet Connection Sharing (ICS) Denial of Service Vulnerability
Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd
CVE-2020-17097P3HIGHCVSS 7.8≥ 10.0.14393.0, < publication2020-12-10
CVE-2020-17097 [HIGH] CVE-2020-17097: Windows Digital Media Receiver Elevation of Privilege Vulnerability
Windows Digital Media Receiver Elevation of Privilege Vulnerability
nvd
CVE-2020-1491P3HIGHCVSS 7.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1491 [HIGH] CVE-2020-1491: <p>An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Ser
An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Service handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update addre
nvd
CVE-2023-21701P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.57172023-02-14
CVE-2023-21701 [HIGH] CWE-126 CVE-2023-21701: Microsoft Protected Extensible Authentication Protocol (PEAP) Denial of Service Vulnerability
Microsoft Protected Extensible Authentication Protocol (PEAP) Denial of Service Vulnerability
nvd
CVE-2023-24901P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.59212023-05-09
CVE-2023-24901 [HIGH] CWE-126 CVE-2023-24901: Windows NFS Portmapper Information Disclosure Vulnerability
Windows NFS Portmapper Information Disclosure Vulnerability
nvd