cbcvebase.

Microsoft Windows 10 Version 1803 vulnerabilities

550 known vulnerabilities affecting microsoft/windows_10_version_1803.

Total CVEs
550
CISA KEV
6
actively exploited
Public exploits
20
Exploited in wild
14
Severity breakdown
CRITICAL16HIGH395MEDIUM138LOW1

Vulnerabilities

Page 2 of 28
CVE-2019-1184P3MEDIUMCVSS 6.7PoC≥ 10.0.0, < publication2019-08-14
CVE-2019-1184 [MEDIUM] CVE-2019-1184: An elevation of privilege vulnerability exists when Windows Core Shell COM Server Registrar improper An elevation of privilege vulnerability exists when Windows Core Shell COM Server Registrar improperly handles COM calls. An attacker who successfully exploited this vulnerability could potentially set certain items to run at a higher level and thereby elevate permissions. To exploit this vulnerability, an attacker would first have to log on to the system. An
nvd
CVE-2019-1019P2HIGHCVSS 8.5PoC≥ 10.0.0, < publication2019-06-12
CVE-2019-1019 [HIGH] CWE-200 CVE-2019-1019: A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the sessio A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages. To exploit this vulnerability, an attacker could send a specially crafted authentication request. An attacker who successfully exploited this vulnerability could access another machine using the original user privileges. The issue
nvd
CVE-2021-28476P2CRITICALCVSS 9.9≥ 10.0.0, < 10.0.17134.22072021-05-11
CVE-2021-28476 [CRITICAL] CVE-2021-28476: Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2020-1337P3HIGHCVSS 7.8PoC≥ 10.0.0, < publication2020-08-17
CVE-2020-1337 [HIGH] CWE-367 CVE-2020-1337: An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly all An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts wit
nvd
CVE-2020-17136P3HIGHCVSS 7.8PoC≥ 10.0.0, < publication2020-12-10
CVE-2020-17136 [HIGH] CVE-2020-17136: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2021-24074P2CRITICALCVSS 9.8≥ 10.0.0, < publication2021-02-25
CVE-2021-24074 [CRITICAL] CVE-2021-24074: Windows TCP/IP Remote Code Execution Vulnerability Windows TCP/IP Remote Code Execution Vulnerability
nvd
CVE-2021-24094P2CRITICALCVSS 9.8≥ 10.0.0, < publication2021-02-25
CVE-2021-24094 [CRITICAL] CVE-2021-24094: Windows TCP/IP Remote Code Execution Vulnerability Windows TCP/IP Remote Code Execution Vulnerability
nvd
CVE-2021-24093P2HIGHCVSS 8.8≥ 10.0.0, < publication2021-02-25
CVE-2021-24093 [HIGH] CVE-2021-24093: Windows Graphics Component Remote Code Execution Vulnerability Windows Graphics Component Remote Code Execution Vulnerability
nvd
CVE-2019-1182P2CRITICALCVSS 9.8≥ 10.0.0, < publication2019-08-14
CVE-2019-1182 [CRITICAL] CVE-2019-1182: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability cou
nvd
CVE-2019-1222P2CRITICALCVSS 9.8≥ 10.0.0, < publication2019-08-14
CVE-2019-1222 [CRITICAL] CVE-2019-1222: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability cou
nvd
CVE-2019-1226P2CRITICALCVSS 9.8≥ 10.0.0, < publication2019-08-14
CVE-2019-1226 [CRITICAL] CVE-2019-1226: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability cou
nvd
CVE-2019-0943P3HIGHCVSS 7.8PoC≥ 10.0.0, < publication2019-06-12
CVE-2019-0943 [HIGH] CVE-2019-0943: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Loc An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user
nvd
CVE-2020-17095P2CRITICALCVSS 9.9≥ 10.0.0, < publication2020-12-10
CVE-2020-17095 [CRITICAL] CVE-2020-17095: Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2020-1074P3HIGHCVSS 7.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1074 [HIGH] CVE-2020-1074: <p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly hand A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerabili
nvd
CVE-2019-0722P2HIGHCVSS 8.8≥ 10.0.0, < publication2019-06-12
CVE-2019-0722 [HIGH] CWE-20 CVE-2019-0722: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary
nvd
CVE-2020-16898P2HIGHCVSS 8.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16898 [HIGH] CVE-2020-16898: <p>A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICM A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could gain the ability to execute code on the target server or client. To exploit this vulnerability, an attacker would have to send specially crafted ICMPv6 Router Adverti
nvd
CVE-2019-0959P3HIGHCVSS 7.0PoC≥ 10.0.0, < publication2019-06-12
CVE-2019-0959 [HIGH] CVE-2019-0959: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted appli
nvd
CVE-2021-24077P2CRITICALCVSS 9.8≥ 10.0.0, < publication2021-02-25
CVE-2021-24077 [CRITICAL] CVE-2021-24077: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2021-1722P2CRITICALCVSS 9.8≥ 10.0.0, < publication2021-02-25
CVE-2021-1722 [CRITICAL] CVE-2021-1722: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2019-1212P3CRITICALCVSS 9.8≥ 10.0.0, < publication2019-08-14
CVE-2019-1212 [CRITICAL] CWE-787 CVE-2019-1212: A memory corruption vulnerability exists in the Windows Server DHCP service when processing speciall A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets. An attacker who successfully exploited the vulnerability could cause the DHCP server service to stop responding. To exploit the vulnerability, a remote unauthenticated attacker could send a specially crafted packet to an affected DH
nvd
Microsoft Windows 10 Version 1803 vulnerabilities | cvebase