Microsoft Windows 10 Version 1803 vulnerabilities
552 known vulnerabilities affecting microsoft/windows_10_version_1803.
Total CVEs
552
CISA KEV
6
actively exploited
Public exploits
17
Exploited in wild
9
Severity breakdown
CRITICAL16HIGH397MEDIUM138LOW1
Vulnerabilities
Page 18 of 28
CVE-2020-1013HIGHCVSS 8.1≥ 10.0.0, < publication2020-09-11
CVE-2020-1013 [HIGH] CVE-2020-1013: <p>An elevation of privilege vulnerability exists when Microsoft Windows processes group policy upda
An elevation of privilege vulnerability exists when Microsoft Windows processes group policy updates. An attacker who successfully exploited this vulnerability could potentially escalate permissions or perform additional privileged actions on the target machine.
To exploit this vulnerability, an attacker would need to launch a man-in-the-middle (MiTM) attack ag
cvelistv5nvd
CVE-2020-1039HIGHCVSS 7.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1039 [HIGH] CVE-2020-1039: <p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly hand
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
cvelistv5nvd
CVE-2020-1052HIGHCVSS 7.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1052 [HIGH] CVE-2020-1052: <p>An elevation of privilege vulnerability exists in the way that the ssdpsrv.dll handles objects in
An elevation of privilege vulnerability exists in the way that the ssdpsrv.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update addresses the vulnerability
cvelistv5nvd
CVE-2020-0998HIGHCVSS 7.8≥ 10.0.0, < publication2020-09-11
CVE-2020-0998 [HIGH] CVE-2020-0998: <p>An elevation of privilege vulnerability exists when the Windows Graphics Component improperly han
An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
In a local attack scenario, an attacker could exploit this vulnerability by running a specially crafted application to take control over the
cvelistv5nvd
CVE-2020-0886HIGHCVSS 7.8≥ 10.0.0, < publication2020-09-11
CVE-2020-0886 [HIGH] CVE-2020-0886: <p>An elevation of privilege vulnerability exists when the Windows Storage Services improperly handl
An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.
To exploit the vulnerability, an attacker would first need code execution on a victim system. An attacker could then run a specially crafted application.
The
cvelistv5nvd
CVE-2020-1130HIGHCVSS 7.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1130 [HIGH] CVE-2020-1130: <p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improp
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
An attacker could exploit this vulnerability by running a specially crafted application on the victim system.
The update addresses the
cvelistv5nvd
CVE-2020-1074HIGHCVSS 7.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1074 [HIGH] CVE-2020-1074: <p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly hand
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
cvelistv5nvd
CVE-2020-1152HIGHCVSS 7.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1152 [HIGH] CVE-2020-1152: <p>An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sy
An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system.
To exploit the vulnerability, an attacker would have to log on to an affected system and run a specially crafted script or application.
The update addres
cvelistv5nvd
CVE-2020-1471HIGHCVSS 7.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1471 [HIGH] CVE-2020-1471: <p>An elevation of privilege vulnerability exists when Microsoft Windows CloudExperienceHost fails t
An elevation of privilege vulnerability exists when Microsoft Windows CloudExperienceHost fails to check COM objects. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system.
To exploit the vulnerability, an attacker would have to log on to an affected system and run a specially crafted script or application.
cvelistv5nvd
CVE-2020-1508HIGHCVSS 8.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1508 [HIGH] CVE-2020-1508: <p>A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles
A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user
cvelistv5nvd
CVE-2020-1319HIGHCVSS 7.8vN/A2020-09-11
CVE-2020-1319 [HIGH] CVE-2020-1319: <p>A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library han
A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
Exploitation of the vuln
cvelistv5nvd
CVE-2020-0782HIGHCVSS 7.8≥ 10.0.0, < publication2020-09-11
CVE-2020-0782 [HIGH] CVE-2020-0782: <p>An elevation of privilege vulnerability exists when the Windows Cryptographic Catalog Services im
An elevation of privilege vulnerability exists when the Windows Cryptographic Catalog Services improperly handle objects in memory. An attacker who successfully exploited this vulnerability could modify the cryptographic catalog.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted a
cvelistv5nvd
CVE-2020-1083MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-09-11
CVE-2020-1083 [MEDIUM] CVE-2020-1083: <p>An information disclosure vulnerability exists when the Microsoft Windows Graphics Component impr
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially c
cvelistv5nvd
CVE-2020-1097MEDIUMCVSS 6.5≥ 10.0.0, < publication2020-09-11
CVE-2020-1097 [MEDIUM] CVE-2020-1097: <p>An information disclosure vulnerability exists when the Windows GDI component improperly disclose
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a speci
cvelistv5nvd
CVE-2020-0904MEDIUMCVSS 6.5≥ 10.0.0, < publication2020-09-11
CVE-2020-0904 [MEDIUM] CWE-20 CVE-2020-0904: <p>A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properl
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system.
To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application.
cvelistv5nvd
CVE-2020-0928MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-09-11
CVE-2020-0928 [MEDIUM] CVE-2020-0928: <p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. T
cvelistv5nvd
CVE-2020-0941MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-09-11
CVE-2020-0941 [MEDIUM] CVE-2020-0941: <p>An information disclosure vulnerability exists when the win32k component improperly provides kern
An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit the vulnerability, an attacker would have to either log on locally to an affected system, or convince a locally au
cvelistv5nvd
CVE-2020-1596MEDIUMCVSS 5.3≥ 10.0.0, < publication2020-09-11
CVE-2020-1596 [MEDIUM] CWE-327 CVE-2020-1596: <p>A information disclosure vulnerability exists when TLS components use weak hash algorithms. An at
A information disclosure vulnerability exists when TLS components use weak hash algorithms. An attacker who successfully exploited this vulnerability could obtain information to further compromise a users's encrypted transmission channel.
To exploit the vulnerability, an attacker would have to conduct a man-in-the-middle attack.
The update addresses t
cvelistv5nvd
CVE-2020-16854MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-09-11
CVE-2020-16854 [MEDIUM] CVE-2020-16854: <p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.
cvelistv5nvd
CVE-2020-1589MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-09-11
CVE-2020-1589 [MEDIUM] CVE-2020-1589: <p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. T
cvelistv5nvd