Microsoft Windows 10 Version 2004 vulnerabilities
755 known vulnerabilities affecting microsoft/windows_10_version_2004.
Total CVEs
755
CISA KEV
26
actively exploited
Public exploits
17
Exploited in wild
34
Severity breakdown
CRITICAL23HIGH553MEDIUM177LOW2
Vulnerabilities
Page 29 of 38
CVE-2021-40463P4MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.19041.12882021-10-13
CVE-2021-40463 [MEDIUM] CVE-2021-40463: Windows Network Address Translation (NAT) Denial of Service Vulnerability
Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2020-1510P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-08-17
CVE-2020-1510 [MEDIUM] CWE-200 CVE-2020-1510: An information disclosure vulnerability exists when the win32k component improperly provides kernel
An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted appl
nvd
CVE-2020-1459P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-08-17
CVE-2020-1459 [MEDIUM] CWE-203 CVE-2020-1459: An information disclosure vulnerability exists on ARM implementations that use speculative execution
An information disclosure vulnerability exists on ARM implementations that use speculative execution in control flow via a side-channel analysis, aka "straight-line speculation."
To exploit this vulnerability, an attacker with local privileges would need to run a specially crafted application.
The security update addresses the vulnerability by bypassi
nvd
CVE-2020-16910P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16910 [MEDIUM] CWE-281 CVE-2020-16910: <p>A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creati
A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location.
To exploit this vulnerability, an attacker could run a specially crafted application to bypass Unified Extensible Firmware
nvd
CVE-2021-34466P4MEDIUMCVSS 6.1≥ 10.0.0, < 10.0.19041.11102021-07-16
CVE-2021-34466 [MEDIUM] CWE-290 CVE-2021-34466: Windows Hello Security Feature Bypass Vulnerability
Windows Hello Security Feature Bypass Vulnerability
nvd
CVE-2021-42288P4MEDIUMCVSS 6.1≥ 10.0.0, < 10.0.19041.13482021-11-10
CVE-2021-42288 [MEDIUM] CVE-2021-42288: Windows Hello Security Feature Bypass Vulnerability
Windows Hello Security Feature Bypass Vulnerability
nvd
CVE-2020-1512P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-08-17
CVE-2020-1512 [MEDIUM] CVE-2020-1512: An information disclosure vulnerability exists when the Windows State Repository Service improperly
An information disclosure vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
An attacker could exploit this vulnerability by running a specially crafted application on the victim system.
T
nvd
CVE-2020-0904P4MEDIUMCVSS 6.5≥ 10.0.0, < publication2020-09-11
CVE-2020-0904 [MEDIUM] CWE-20 CVE-2020-0904: <p>A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properl
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system.
To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application.
nvd
CVE-2021-1683P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2021-01-12
CVE-2021-1683 [MEDIUM] CVE-2021-1683: Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For
Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG.
To address the vulnerability, Microsoft has released a software update that will fail attempts to pair if the remote device exchanges a public key with the same X coordinate
nvd
CVE-2021-1684P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2021-01-12
CVE-2021-1684 [MEDIUM] CVE-2021-1684: Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For
Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG.
To address the vulnerability, Microsoft has released a software update that will fail attempts to pair if the remote device exchanges a public key with the same X coordinate
nvd
CVE-2020-16914P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16914 [MEDIUM] CVE-2020-16914: <p>An information disclosure vulnerability exists in the way that the Windows Graphics Device Interf
An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface Plus (GDI+) handles objects in memory, allowing an attacker to retrieve information from a targeted system. By itself, the information disclosure does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses i
nvd
CVE-2021-43224P4MEDIUMCVSS 5.5≥ 10.0.0, < 10.0.19041.14152021-12-15
CVE-2021-43224 [MEDIUM] CVE-2021-43224: Windows Common Log File System Driver Information Disclosure Vulnerability
Windows Common Log File System Driver Information Disclosure Vulnerability
nvd
CVE-2021-27079P4MEDIUMCVSS 5.7≥ 10.0.0, < publication2021-04-13
CVE-2021-27079 [MEDIUM] CVE-2021-27079: Windows Media Photo Codec Information Disclosure Vulnerability
Windows Media Photo Codec Information Disclosure Vulnerability
nvd
CVE-2021-26866P4MEDIUMCVSS 6.1≥ 10.0.0, < publication2021-03-11
CVE-2021-26866 [MEDIUM] CWE-59 CVE-2021-26866: Windows Update Service Elevation of Privilege Vulnerability
Windows Update Service Elevation of Privilege Vulnerability
nvd
CVE-2020-16938P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16938 [MEDIUM] CVE-2020-16938: <p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.
nvd
CVE-2021-1645P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2021-01-12
CVE-2021-1645 [MEDIUM] CVE-2021-1645: Windows Docker Information Disclosure Vulnerability
Windows Docker Information Disclosure Vulnerability
nvd
CVE-2021-1638P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2021-01-12
CVE-2021-1638 [MEDIUM] CVE-2021-1638: Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For
Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG.
To address the vulnerability, Microsoft has released a software update that will fail attempts to pair if the remote device exchanges a public key with the same X coordinate
nvd
CVE-2020-1383P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-08-17
CVE-2020-1383 [MEDIUM] CVE-2020-1383: An information disclosure vulnerability exists in RPC if the server has Routing and Remote Access en
An information disclosure vulnerability exists in RPC if the server has Routing and Remote Access enabled. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system
To exploit this vulnerability, an attacker would need to run a specially crafted application against an RPC server which has Routin
nvd
CVE-2021-1731P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2021-02-25
CVE-2021-1731 [MEDIUM] CWE-522 CVE-2021-1731: PFX Encryption Security Feature Bypass Vulnerability
PFX Encryption Security Feature Bypass Vulnerability
nvd
CVE-2020-16922P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16922 [MEDIUM] CWE-347 CVE-2020-16922: <p>A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker w
A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files.
In an attack scenario, an attacker could bypass security features intended to prevent improperly signed files from being loaded.
The update addr
nvd