Microsoft Windows 10 Version 1709 vulnerabilities
269 known vulnerabilities affecting microsoft/windows_10_version_1709.
Total CVEs
269
CISA KEV
3
actively exploited
Public exploits
15
Exploited in wild
6
Severity breakdown
CRITICAL4HIGH200MEDIUM65
Vulnerabilities
Page 2 of 14
CVE-2019-1212P3CRITICALCVSS 9.8≥ 10.0.0, < publication2019-08-14
CVE-2019-1212 [CRITICAL] CWE-787 CVE-2019-1212: A memory corruption vulnerability exists in the Windows Server DHCP service when processing speciall
A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets. An attacker who successfully exploited the vulnerability could cause the DHCP server service to stop responding.
To exploit the vulnerability, a remote unauthenticated attacker could send a specially crafted packet to an affected DH
nvd
CVE-2019-0736P3CRITICALCVSS 9.8≥ 10.0.0, < publication2019-08-14
CVE-2019-0736 [CRITICAL] CWE-787 CVE-2019-0736: A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client. An attacker who successfully exploited the vulnerability could run arbitrary code on the client machine.
To exploit the vulnerability, an attacker could send specially crafted DHCP responses to a client.
The securi
nvd
CVE-2019-0888P3HIGHCVSS 8.8≥ 10.0.0, < publication2019-06-12
CVE-2019-0888 [HIGH] CVE-2019-0888: A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objec
A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with the victim user’s privileges.
An attacker could craft a website that exploits the vulnerability and then convince a victim user to visit the website.
The secu
nvd
CVE-2020-16911P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16911 [HIGH] CVE-2020-16911: <p>A remote code execution vulnerability exists in the way that the Windows Graphics Device Interfac
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users w
nvd
CVE-2019-1125P3MEDIUMCVSS 5.6PoC≥ 10.0.0, < publication2019-09-03
CVE-2019-1125 [MEDIUM] CVE-2019-1125: An information disclosure vulnerability exists when certain central processing units (CPU) speculati
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The v
nvd
CVE-2020-1285P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1285 [HIGH] CVE-2020-1285: <p>A remote code execution vulnerability exists in the way that the Windows Graphics Device Interfac
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users who
nvd
CVE-2020-1509P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1509 [HIGH] CVE-2020-1509: An elevation of privilege vulnerability exists in the Local Security Authority Subsystem Service (LS
An elevation of privilege vulnerability exists in the Local Security Authority Subsystem Service (LSASS) when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could cause an elevation of privilege on the target system's LSASS service.
The security update addresses the vul
nvd
CVE-2020-0922P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-09-11
CVE-2020-0922 [HIGH] CVE-2020-0922: <p>A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles ob
A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system.
To exploit the vulnerability, a user would have to open a specially crafted file or lure the target to a website hosting malicious JavaScript.
nvd
CVE-2020-1561P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1561 [HIGH] CVE-2020-1561: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system.
To exploit the vulnerability, a user would have to open a specially crafted file.
The security update addresses the vulnerability by correct
nvd
CVE-2020-1339P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1339 [HIGH] CVE-2020-1339: A remote code execution vulnerability exists when Windows Media Audio Codec improperly handles objec
A remote code execution vulnerability exists when Windows Media Audio Codec improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user
nvd
CVE-2020-1508P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1508 [HIGH] CVE-2020-1508: <p>A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles
A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user
nvd
CVE-2020-16915P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16915 [HIGH] CWE-787 CVE-2020-16915: <p>A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights.
There are multiple ways an attacker could exploit the vulnerability, such as by convinc
nvd
CVE-2020-1585P3HIGHCVSS 8.8vN/A2020-08-17
CVE-2020-1585 [HIGH] CVE-2020-1585: A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handle
A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
Exploitation of the vuln
nvd
CVE-2020-16899P3HIGHCVSS 7.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16899 [HIGH] CVE-2020-16899: <p>A denial of service vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6
A denial of service vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could cause a target system to stop responding.
To exploit this vulnerability, an attacker would have to send specially crafted ICMPv6 Router Advertisement packets to a remote W
nvd
CVE-2020-1593P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1593 [HIGH] CVE-2020-1593: <p>A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles
A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user
nvd
CVE-2019-0720P3HIGHCVSS 8.0≥ 10.0.0, < publication2019-08-14
CVE-2019-0720 [HIGH] CWE-20 CVE-2019-0720: A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fa
A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to exe
nvd
CVE-2020-16891P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16891 [HIGH] CWE-20 CVE-2020-16891: <p>A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to prope
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrar
nvd
CVE-2019-1153P4MEDIUMCVSS 5.5PoC≥ 10.0.0, < publication2019-08-14
CVE-2019-1153 [MEDIUM] CWE-125 CVE-2019-1153: An information disclosure vulnerability exists when the Microsoft Windows Graphics Component imprope
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a spe
nvd
CVE-2019-1148P4MEDIUMCVSS 5.5PoC≥ 10.0.0, < publication2019-08-14
CVE-2019-1148 [MEDIUM] CWE-125 CVE-2019-1148: An information disclosure vulnerability exists when the Microsoft Windows Graphics Component imprope
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a spe
nvd
CVE-2020-1013P3HIGHCVSS 8.1≥ 10.0.0, < publication2020-09-11
CVE-2020-1013 [HIGH] CVE-2020-1013: <p>An elevation of privilege vulnerability exists when Microsoft Windows processes group policy upda
An elevation of privilege vulnerability exists when Microsoft Windows processes group policy updates. An attacker who successfully exploited this vulnerability could potentially escalate permissions or perform additional privileged actions on the target machine.
To exploit this vulnerability, an attacker would need to launch a man-in-the-middle (MiTM) attack ag
nvd