Microsoft Windows 10 Version 1909 vulnerabilities
966 known vulnerabilities affecting microsoft/windows_10_version_1909.
Total CVEs
966
CISA KEV
33
actively exploited
Public exploits
26
Exploited in wild
48
Severity breakdown
CRITICAL31HIGH718MEDIUM214LOW3
Vulnerabilities
Page 35 of 49
CVE-2020-16997P4MEDIUMCVSS 6.5≥ 10.0.0, < publication2020-11-11
CVE-2020-16997 [MEDIUM] CVE-2020-16997: Remote Desktop Protocol Server Information Disclosure Vulnerability
Remote Desktop Protocol Server Information Disclosure Vulnerability
nvd
CVE-2020-1487P3MEDIUMCVSS 6.5≥ 10.0.0, < publication2020-08-17
CVE-2020-1487 [MEDIUM] CVE-2020-1487: An information disclosure vulnerability exists when Media Foundation improperly handles objects in m
An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log onto an affected system and open a specially crafted file. In a web-b
nvd
CVE-2021-43216P3MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.18363.19772021-12-15
CVE-2021-43216 [MEDIUM] CWE-668 CVE-2021-43216: Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
nvd
CVE-2021-43237P3HIGHCVSS 7.3≥ 10.0.0, < 10.0.18363.19772021-12-15
CVE-2021-43237 [HIGH] CWE-59 CVE-2021-43237: Windows Setup Elevation of Privilege Vulnerability
Windows Setup Elevation of Privilege Vulnerability
nvd
CVE-2022-21863P4HIGHCVSS 7.0≥ 10.0.0, < 10.0.18363.20372022-01-11
CVE-2022-21863 [HIGH] CVE-2022-21863: Windows StateRepository API Server file Elevation of Privilege Vulnerability
Windows StateRepository API Server file Elevation of Privilege Vulnerability
nvd
CVE-2021-38665P4MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.18363.19162021-11-10
CVE-2021-38665 [MEDIUM] CVE-2021-38665: Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability
nvd
CVE-2022-26936P3MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.18363.22742022-05-10
CVE-2022-26936 [MEDIUM] CVE-2022-26936: Windows Server Service Information Disclosure Vulnerability
Windows Server Service Information Disclosure Vulnerability
nvd
CVE-2022-22015P3MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.18363.22742022-05-10
CVE-2022-22015 [MEDIUM] CVE-2022-22015: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
nvd
CVE-2022-21864P4HIGHCVSS 7.0≥ 10.0.0, < 10.0.18363.20372022-01-11
CVE-2022-21864 [HIGH] CVE-2022-21864: Windows UI Immersive Server API Elevation of Privilege Vulnerability
Windows UI Immersive Server API Elevation of Privilege Vulnerability
nvd
CVE-2022-21860P4HIGHCVSS 7.0≥ 10.0.0, < 10.0.18363.20372022-01-11
CVE-2022-21860 [HIGH] CVE-2022-21860: Windows AppContracts API Server Elevation of Privilege Vulnerability
Windows AppContracts API Server Elevation of Privilege Vulnerability
nvd
CVE-2020-0875P3MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-09-11
CVE-2020-0875 [MEDIUM] CVE-2020-0875: <p>An information disclosure vulnerability exists in how splwow64.exe handles certain calls. An atta
An information disclosure vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system (low-integrity to medium-integrity).
This vulnerability by itself does not allow arbitrary code execution; however, it could allow arbitrary code to
nvd
CVE-2022-23298P4HIGHCVSS 7.0≥ 10.0.0, < 10.0.18363.21582022-03-09
CVE-2022-23298 [HIGH] CVE-2022-23298: Windows NT OS Kernel Elevation of Privilege Vulnerability
Windows NT OS Kernel Elevation of Privilege Vulnerability
nvd
CVE-2020-0837P4MEDIUMCVSS 5.3≥ 10.0.0, < publication2020-09-11
CVE-2020-0837 [MEDIUM] CVE-2020-0837: <p>An elevation of privilege vulnerability exists when Active Directory Federation Services (ADFS) i
An elevation of privilege vulnerability exists when Active Directory Federation Services (ADFS) improperly handles multi-factor authentication requests. An attacker who successfully exploited this vulnerability could bypass some, but not all, of the authentication factors.
To exploit this vulnerability, an attacker could send a specially crafted authenticatio
nvd
CVE-2021-41332P4MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.18363.18542021-10-13
CVE-2021-41332 [MEDIUM] CVE-2021-41332: Windows Print Spooler Information Disclosure Vulnerability
Windows Print Spooler Information Disclosure Vulnerability
nvd
CVE-2021-38629P4MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.18363.18012021-09-15
CVE-2021-38629 [MEDIUM] CVE-2021-38629: Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
nvd
CVE-2022-21865P4HIGHCVSS 7.0≥ 10.0.0, < 10.0.18363.20372022-01-11
CVE-2022-21865 [HIGH] CVE-2022-21865: Connected Devices Platform Service Elevation of Privilege Vulnerability
Connected Devices Platform Service Elevation of Privilege Vulnerability
nvd
CVE-2022-21967P4HIGHCVSS 7.0≥ 10.0.0, < 10.0.18363.21582022-03-09
CVE-2022-21967 [HIGH] CVE-2022-21967: Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability
Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability
nvd
CVE-2022-21862P4HIGHCVSS 7.0≥ 10.0.0, < 10.0.18363.20372022-01-11
CVE-2022-21862 [HIGH] CVE-2022-21862: Windows Application Model Core API Elevation of Privilege Vulnerability
Windows Application Model Core API Elevation of Privilege Vulnerability
nvd
CVE-2022-26808P4HIGHCVSS 7.0≥ 10.0.0, < 10.0.18363.22122022-04-15
CVE-2022-26808 [HIGH] CWE-362 CVE-2022-26808: Windows File Explorer Elevation of Privilege Vulnerability
Windows File Explorer Elevation of Privilege Vulnerability
nvd
CVE-2022-26827P4HIGHCVSS 7.0≥ 10.0.0, < 10.0.18363.22122022-04-15
CVE-2022-26827 [HIGH] CWE-362 CVE-2022-26827: Windows File Server Resource Management Service Elevation of Privilege Vulnerability
Windows File Server Resource Management Service Elevation of Privilege Vulnerability
nvd