Microsoft Windows 10 Version 1909 vulnerabilities
966 known vulnerabilities affecting microsoft/windows_10_version_1909.
Total CVEs
966
CISA KEV
33
actively exploited
Public exploits
26
Exploited in wild
48
Severity breakdown
CRITICAL31HIGH718MEDIUM214LOW3
Vulnerabilities
Page 10 of 49
CVE-2020-1013P3HIGHCVSS 8.1≥ 10.0.0, < publication2020-09-11
CVE-2020-1013 [HIGH] CVE-2020-1013: <p>An elevation of privilege vulnerability exists when Microsoft Windows processes group policy upda
An elevation of privilege vulnerability exists when Microsoft Windows processes group policy updates. An attacker who successfully exploited this vulnerability could potentially escalate permissions or perform additional privileged actions on the target machine.
To exploit this vulnerability, an attacker would need to launch a man-in-the-middle (MiTM) attack ag
nvd
CVE-2022-22715P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.18363.20942022-02-09
CVE-2022-22715 [HIGH] CWE-191 CVE-2022-22715: Named Pipe File System Elevation of Privilege Vulnerability
Named Pipe File System Elevation of Privilege Vulnerability
nvd
CVE-2020-1129P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1129 [HIGH] CVE-2020-1129: <p>A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library han
A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
Exploitation of the vuln
nvd
CVE-2022-24533P3HIGHCVSS 8.0≥ 10.0.0, < 10.0.18363.22122022-04-15
CVE-2022-24533 [HIGH] CVE-2022-24533: Remote Desktop Protocol Remote Code Execution Vulnerability
Remote Desktop Protocol Remote Code Execution Vulnerability
nvd
CVE-2022-21920P3HIGHCVSS 8.8≥ 10.0.0, < 10.0.18363.20372022-01-11
CVE-2022-21920 [HIGH] CVE-2022-21920: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2021-1706P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-01-12
CVE-2021-1706 [HIGH] CWE-269 CVE-2021-1706: Windows LUAFV Elevation of Privilege Vulnerability
Windows LUAFV Elevation of Privilege Vulnerability
nvd
CVE-2021-26863P3HIGHCVSS 7.8≥ 10.0.0, < publication2021-03-11
CVE-2021-26863 [HIGH] CWE-269 CVE-2021-26863: Windows Win32k Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
nvd
CVE-2022-29104P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.18363.22742022-05-10
CVE-2022-29104 [HIGH] CVE-2022-29104: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2021-43883P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.18363.19772021-12-15
CVE-2021-43883 [HIGH] CVE-2021-43883: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2020-17162P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-02-25
CVE-2020-17162 [HIGH] CVE-2020-17162: Microsoft Windows Security Feature Bypass Vulnerability
Microsoft Windows Security Feature Bypass Vulnerability
nvd
CVE-2022-24500HIGHCVSS 8.8ExploitedRansomware≥ 10.0.0, < 10.0.18363.22122022-04-15
CVE-2022-24500 [HIGH] Windows SMB Remote Code Execution Vulnerability
Windows SMB Remote Code Execution Vulnerability
Windows SMB Remote Code Execution Vulnerability
cvelistv5
CVE-2020-17047P3HIGHCVSS 7.5≥ 10.0.0, < publication2020-11-11
CVE-2020-17047 [HIGH] CVE-2020-17047: Windows Network File System Denial of Service Vulnerability
Windows Network File System Denial of Service Vulnerability
nvd
CVE-2021-43893P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.18363.19772021-12-15
CVE-2021-43893 [HIGH] CWE-668 CVE-2021-43893: Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability
Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability
nvd
CVE-2021-31971P3HIGHCVSS 8.8≥ 10.0.0, < 10.0.18363.16212021-06-08
CVE-2021-31971 [HIGH] CVE-2021-31971: Windows HTML Platforms Security Feature Bypass Vulnerability
Windows HTML Platforms Security Feature Bypass Vulnerability
nvd
CVE-2020-1031P3HIGHCVSS 7.5≥ 10.0.0, < publication2020-09-11
CVE-2020-1031 [HIGH] CVE-2020-1031: <p>An information disclosure vulnerability exists in the way that the Windows Server DHCP service im
An information disclosure vulnerability exists in the way that the Windows Server DHCP service improperly discloses the contents of its memory.
To exploit the vulnerability, an unauthenticated attacker could send a specially crafted packet to an affected DHCP server. An attacker who successfully exploited this vulnerability could obtain information to further c
nvd
CVE-2021-34446P3HIGHCVSS 8.8≥ 10.0.0, < 10.0.18363.16792021-07-16
CVE-2021-34446 [HIGH] CVE-2021-34446: Windows HTML Platforms Security Feature Bypass Vulnerability
Windows HTML Platforms Security Feature Bypass Vulnerability
nvd
CVE-2022-24542P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.18363.22122022-04-15
CVE-2022-24542 [HIGH] CVE-2022-24542: Windows Win32k Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
nvd
CVE-2022-26826P3HIGHCVSS 7.2≥ 10.0.0, < 10.0.18363.22122022-04-15
CVE-2022-26826 [HIGH] CWE-77 CVE-2022-26826: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2022-24495P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.18363.22122022-04-15
CVE-2022-24495 [HIGH] CVE-2022-24495: Windows Direct Show Remote Code Execution Vulnerability
Windows Direct Show Remote Code Execution Vulnerability
nvd
CVE-2020-1525P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1525 [HIGH] CWE-787 CVE-2020-1525: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights.
There are multiple ways an attacker could exploit the vulnerability, such as by convincin
nvd