cbcvebase.

Microsoft Windows 10 Version 1909 vulnerabilities

966 known vulnerabilities affecting microsoft/windows_10_version_1909.

Total CVEs
966
CISA KEV
33
actively exploited
Public exploits
26
Exploited in wild
48
Severity breakdown
CRITICAL31HIGH718MEDIUM214LOW3

Vulnerabilities

Page 37 of 49
CVE-2020-0890P4MEDIUMCVSS 6.5≥ 10.0.0, < publication2020-09-11
CVE-2020-0890 [MEDIUM] CVE-2020-0890: <p>A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properl A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application. The sec
nvd
CVE-2022-26934P4MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.18363.22742022-05-10
CVE-2022-26934 [MEDIUM] CVE-2022-26934: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2020-16877P4HIGHCVSS 7.1≥ 10.0.0, < publication2020-10-16
CVE-2020-16877 [HIGH] CVE-2020-16877: <p>An elevation of privilege vulnerability exists when Microsoft Windows improperly handles reparse An elevation of privilege vulnerability exists when Microsoft Windows improperly handles reparse points. An attacker who successfully exploited this vulnerability could overwrite or delete a targeted file that would normally require elevated permissions. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then
nvd
CVE-2020-17014P4HIGHCVSS 7.1≥ 10.0.0, < publication2020-11-11
CVE-2020-17014 [HIGH] CVE-2020-17014: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-21997P4HIGHCVSS 7.1≥ 10.0.0, < 10.0.18363.20942022-02-09
CVE-2022-21997 [HIGH] CWE-59 CVE-2022-21997: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2021-34493P4MEDIUMCVSS 6.7≥ 10.0.0, < 10.0.18363.16792021-07-14
CVE-2021-34493 [MEDIUM] CWE-269 CVE-2021-34493: Windows Partition Management Driver Elevation of Privilege Vulnerability Windows Partition Management Driver Elevation of Privilege Vulnerability
nvd
CVE-2021-41338P4MEDIUMCVSS 5.5≥ 10.0.0, < 10.0.18363.18542021-10-13
CVE-2021-41338 [MEDIUM] CVE-2021-41338: Windows AppContainer Firewall Rules Security Feature Bypass Vulnerability Windows AppContainer Firewall Rules Security Feature Bypass Vulnerability
nvd
CVE-2020-16919P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16919 [MEDIUM] CVE-2020-16919: <p>An information disclosure vulnerability exists when the Windows Enterprise App Management Service An information disclosure vulnerability exists when the Windows Enterprise App Management Service improperly handles certain file operations. An attacker who successfully exploited this vulnerability could read arbitrary files. An attacker with unprivileged access to a vulnerable system could exploit this vulnerability. The security update addresses the vul
nvd
CVE-2021-40463P4MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.18363.18542021-10-13
CVE-2021-40463 [MEDIUM] CVE-2021-40463: Windows Network Address Translation (NAT) Denial of Service Vulnerability Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2020-1510P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-08-17
CVE-2020-1510 [MEDIUM] CWE-200 CVE-2020-1510: An information disclosure vulnerability exists when the win32k component improperly provides kernel An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted appl
nvd
CVE-2020-1459P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-08-17
CVE-2020-1459 [MEDIUM] CWE-203 CVE-2020-1459: An information disclosure vulnerability exists on ARM implementations that use speculative execution An information disclosure vulnerability exists on ARM implementations that use speculative execution in control flow via a side-channel analysis, aka "straight-line speculation." To exploit this vulnerability, an attacker with local privileges would need to run a specially crafted application. The security update addresses the vulnerability by bypassi
nvd
CVE-2022-21960P4MEDIUMCVSS 6.8≥ 10.0.0, < 10.0.18363.20372022-01-11
CVE-2022-21960 [MEDIUM] CVE-2022-21960: Windows Resilient File System (ReFS) Remote Code Execution Vulnerability Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
nvd
CVE-2022-21959P4MEDIUMCVSS 6.8≥ 10.0.0, < 10.0.18363.20372022-01-11
CVE-2022-21959 [MEDIUM] CVE-2022-21959: Windows Resilient File System (ReFS) Remote Code Execution Vulnerability Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
nvd
CVE-2022-21892P4MEDIUMCVSS 6.8≥ 10.0.0, < 10.0.18363.20372022-01-11
CVE-2022-21892 [MEDIUM] CVE-2022-21892: Windows Resilient File System (ReFS) Remote Code Execution Vulnerability Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
nvd
CVE-2022-21958P4MEDIUMCVSS 6.8≥ 10.0.0, < 10.0.18363.20372022-01-11
CVE-2022-21958 [MEDIUM] CVE-2022-21958: Windows Resilient File System (ReFS) Remote Code Execution Vulnerability Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
nvd
CVE-2022-21961P4MEDIUMCVSS 6.8≥ 10.0.0, < 10.0.18363.20372022-01-11
CVE-2022-21961 [MEDIUM] CVE-2022-21961: Windows Resilient File System (ReFS) Remote Code Execution Vulnerability Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
nvd
CVE-2022-21962P4MEDIUMCVSS 6.8≥ 10.0.0, < 10.0.18363.20372022-01-11
CVE-2022-21962 [MEDIUM] CVE-2022-21962: Windows Resilient File System (ReFS) Remote Code Execution Vulnerability Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
nvd
CVE-2022-21963P4MEDIUMCVSS 6.8≥ 10.0.0, < 10.0.18363.20372022-01-11
CVE-2022-21963 [MEDIUM] CVE-2022-21963: Windows Resilient File System (ReFS) Remote Code Execution Vulnerability Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
nvd
CVE-2020-16910P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16910 [MEDIUM] CWE-281 CVE-2020-16910: <p>A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creati A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location. To exploit this vulnerability, an attacker could run a specially crafted application to bypass Unified Extensible Firmware
nvd
CVE-2021-34466P4MEDIUMCVSS 6.1≥ 10.0.0, < 10.0.18363.16792021-07-16
CVE-2021-34466 [MEDIUM] CWE-290 CVE-2021-34466: Windows Hello Security Feature Bypass Vulnerability Windows Hello Security Feature Bypass Vulnerability
nvd
Microsoft Windows 10 Version 1909 vulnerabilities | cvebase