Microsoft Windows 10 Version 1709 For 32-Bit Systems vulnerabilities
256 known vulnerabilities affecting microsoft/windows_10_version_1709_for_32-bit_systems.
Total CVEs
256
CISA KEV
3
actively exploited
Public exploits
2
Exploited in wild
4
Severity breakdown
CRITICAL4HIGH190MEDIUM62
Vulnerabilities
Page 1 of 13
CVE-2020-16976HIGHCVSS 7.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16976 [HIGH] CVE-2020-16976: <p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles
An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability by correcting ho
cvelistv5nvd
CVE-2020-16900HIGHCVSS 7.0≥ 10.0.0, < publication2020-10-16
CVE-2020-16900 [HIGH] CVE-2020-16900: <p>An elevation of privilege vulnerability exists when the Windows Event System improperly handles o
An elevation of privilege vulnerability exists when the Windows Event System improperly handles objects in memory.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability by correcting ho
cvelistv5nvd
CVE-2020-17022HIGHCVSS 7.8vN/A2020-10-16
CVE-2020-17022 [HIGH] CVE-2020-17022: <p>A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library han
A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code.
Exploitation of the vulnerability requires that a program process a specially crafted image file.
The update addresses the vulnerability by correcting ho
cvelistv5nvd
CVE-2020-16975HIGHCVSS 7.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16975 [HIGH] CVE-2020-16975: <p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles
An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability by correcting ho
cvelistv5nvd
CVE-2020-16898HIGHCVSS 8.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16898 [HIGH] CVE-2020-16898: <p>A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICM
A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could gain the ability to execute code on the target server or client.
To exploit this vulnerability, an attacker would have to send specially crafted ICMPv6 Router Adverti
cvelistv5nvd
CVE-2020-16890HIGHCVSS 7.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16890 [HIGH] CVE-2020-16890: <p>An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle o
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability,
cvelistv5nvd
CVE-2020-16924HIGHCVSS 7.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16924 [HIGH] CVE-2020-16924: <p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly hand
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabi
cvelistv5nvd
CVE-2020-16912HIGHCVSS 7.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16912 [HIGH] CVE-2020-16912: <p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles
An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability by correcting ho
cvelistv5nvd
CVE-2020-16896HIGHCVSS 7.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16896 [HIGH] CVE-2020-16896: <p>An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker
An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would need to run a
cvelistv5nvd
CVE-2020-16913HIGHCVSS 7.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16913 [HIGH] CVE-2020-16913: <p>An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fai
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To expl
cvelistv5nvd
CVE-2020-16920HIGHCVSS 7.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16920 [HIGH] CVE-2020-16920: <p>An elevation of privilege vulnerability exists when the Windows Application Compatibility Client
An elevation of privilege vulnerability exists when the Windows Application Compatibility Client Library improperly handles registry operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.
To exploit the vulnerability, an attacker would first need code execution on a victim system. An attacker could then run a spec
cvelistv5nvd
CVE-2020-1167HIGHCVSS 7.8≥ 10.0.0, < publication2020-10-16
CVE-2020-1167 [HIGH] CWE-20 CVE-2020-1167: <p>A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system.
To exploit the vulnerability, a user would have to open a specially crafted file.
The security update addresses the vulnerability by
cvelistv5nvd
CVE-2020-16887HIGHCVSS 7.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16887 [HIGH] CVE-2020-16887: <p>An elevation of privilege vulnerability exists in the way that the Windows Network Connections Se
An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update ad
cvelistv5nvd
CVE-2020-16940HIGHCVSS 7.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16940 [HIGH] CWE-269 CVE-2020-16940: <p>An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) im
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then r
cvelistv5nvd
CVE-2020-16876HIGHCVSS 7.1≥ 10.0.0, < publication2020-10-16
CVE-2020-16876 [HIGH] CVE-2020-16876: <p>An elevation of privilege vulnerability exists when the Windows Application Compatibility Client
An elevation of privilege vulnerability exists when the Windows Application Compatibility Client Library improperly handles registry operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.
To exploit the vulnerability, an attacker would first need code execution on a victim system. An attacker could then run a spec
cvelistv5nvd
CVE-2020-16967HIGHCVSS 7.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16967 [HIGH] CVE-2020-16967: <p>A remote code execution vulnerability exists when the Windows Camera Codec Pack improperly handle
A remote code execution vulnerability exists when the Windows Camera Codec Pack improperly handles objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An a
cvelistv5nvd
CVE-2020-16909HIGHCVSS 7.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16909 [HIGH] CVE-2020-16909: <p>An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it.
An attacker who successfully exploited the vulnerability could gain greater access to sensitive information and system functionality. To exploit the
cvelistv5nvd
CVE-2020-16923HIGHCVSS 7.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16923 [HIGH] CVE-2020-16923: <p>A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system.
To exploit the vulnerability, a user would have to open a specially crafted file.
The security update addresses the vulnerability by corre
cvelistv5nvd
CVE-2020-0764HIGHCVSS 7.8≥ 10.0.0, < publication2020-10-16
CVE-2020-0764 [HIGH] CVE-2020-0764: <p>An elevation of privilege vulnerability exists when the Windows Storage Services improperly handl
An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.
To exploit the vulnerability, an attacker would first need code execution on a victim system. An attacker could then run a specially crafted application.
The
cvelistv5nvd
CVE-2020-16899HIGHCVSS 7.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16899 [HIGH] CVE-2020-16899: <p>A denial of service vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6
A denial of service vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could cause a target system to stop responding.
To exploit this vulnerability, an attacker would have to send specially crafted ICMPv6 Router Advertisement packets to a remote W
cvelistv5nvd
1 / 13Next →