Microsoft Windows 10 Version 1803 vulnerabilities
550 known vulnerabilities affecting microsoft/windows_10_version_1803.
Total CVEs
550
CISA KEV
6
actively exploited
Public exploits
20
Exploited in wild
14
Severity breakdown
CRITICAL16HIGH395MEDIUM138LOW1
Vulnerabilities
Page 5 of 28
CVE-2021-28354P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-04-13
CVE-2021-28354 [HIGH] CVE-2021-28354: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28334P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-04-13
CVE-2021-28334 [HIGH] CVE-2021-28334: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28358P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-04-13
CVE-2021-28358 [HIGH] CVE-2021-28358: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28357P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-04-13
CVE-2021-28357 [HIGH] CVE-2021-28357: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28336P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-04-13
CVE-2021-28336 [HIGH] CVE-2021-28336: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28353P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-04-13
CVE-2021-28353 [HIGH] CVE-2021-28353: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-26881P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-03-11
CVE-2021-26881 [HIGH] CVE-2021-26881: Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
nvd
CVE-2019-1125P3MEDIUMCVSS 5.6PoC≥ 10.0.0, < publication2019-09-03
CVE-2019-1125 [MEDIUM] CVE-2019-1125: An information disclosure vulnerability exists when certain central processing units (CPU) speculati
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The v
nvd
CVE-2020-17090P3CRITICALCVSS 9.8≥ 10.0.0, < publication2020-11-11
CVE-2020-17090 [CRITICAL] CVE-2020-17090: Microsoft Defender for Endpoint Security Feature Bypass Vulnerability
Microsoft Defender for Endpoint Security Feature Bypass Vulnerability
nvd
CVE-2020-17040P3CRITICALCVSS 9.8≥ 10.0.0, < publication2020-11-11
CVE-2020-17040 [CRITICAL] CVE-2020-17040: Windows Hyper-V Security Feature Bypass Vulnerability
Windows Hyper-V Security Feature Bypass Vulnerability
nvd
CVE-2020-1285P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1285 [HIGH] CVE-2020-1285: <p>A remote code execution vulnerability exists in the way that the Windows Graphics Device Interfac
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users who
nvd
CVE-2020-1509P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1509 [HIGH] CVE-2020-1509: An elevation of privilege vulnerability exists in the Local Security Authority Subsystem Service (LS
An elevation of privilege vulnerability exists in the Local Security Authority Subsystem Service (LSASS) when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could cause an elevation of privilege on the target system's LSASS service.
The security update addresses the vul
nvd
CVE-2021-1694P3CRITICALCVSS 9.8≥ 10.0.0, < publication2021-01-12
CVE-2021-1694 [CRITICAL] CWE-269 CVE-2021-1694: Windows Update Stack Elevation of Privilege Vulnerability
Windows Update Stack Elevation of Privilege Vulnerability
nvd
CVE-2020-0922P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-09-11
CVE-2020-0922 [HIGH] CVE-2020-0922: <p>A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles ob
A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system.
To exploit the vulnerability, a user would have to open a specially crafted file or lure the target to a website hosting malicious JavaScript.
nvd
CVE-2020-1561P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1561 [HIGH] CVE-2020-1561: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system.
To exploit the vulnerability, a user would have to open a specially crafted file.
The security update addresses the vulnerability by correct
nvd
CVE-2020-1339P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1339 [HIGH] CVE-2020-1339: A remote code execution vulnerability exists when Windows Media Audio Codec improperly handles objec
A remote code execution vulnerability exists when Windows Media Audio Codec improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user
nvd
CVE-2020-1508P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1508 [HIGH] CVE-2020-1508: <p>A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles
A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user
nvd
CVE-2020-16915P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16915 [HIGH] CWE-787 CVE-2020-16915: <p>A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights.
There are multiple ways an attacker could exploit the vulnerability, such as by convinc
nvd
CVE-2020-1585P3HIGHCVSS 8.8vN/A2020-08-17
CVE-2020-1585 [HIGH] CVE-2020-1585: A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handle
A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
Exploitation of the vuln
nvd
CVE-2020-16899P3HIGHCVSS 7.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16899 [HIGH] CVE-2020-16899: <p>A denial of service vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6
A denial of service vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could cause a target system to stop responding.
To exploit this vulnerability, an attacker would have to send specially crafted ICMPv6 Router Advertisement packets to a remote W
nvd