Microsoft Windows 10 Version 2004 vulnerabilities
755 known vulnerabilities affecting microsoft/windows_10_version_2004.
Total CVEs
755
CISA KEV
26
actively exploited
Public exploits
17
Exploited in wild
34
Severity breakdown
CRITICAL23HIGH553MEDIUM177LOW2
Vulnerabilities
Page 6 of 38
CVE-2021-28357P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-04-13
CVE-2021-28357 [HIGH] CVE-2021-28357: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28336P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-04-13
CVE-2021-28336 [HIGH] CVE-2021-28336: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28353P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-04-13
CVE-2021-28353 [HIGH] CVE-2021-28353: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-26881P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-03-11
CVE-2021-26881 [HIGH] CVE-2021-26881: Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
nvd
CVE-2020-17090P3CRITICALCVSS 9.8≥ 10.0.0, < publication2020-11-11
CVE-2020-17090 [CRITICAL] CVE-2020-17090: Microsoft Defender for Endpoint Security Feature Bypass Vulnerability
Microsoft Defender for Endpoint Security Feature Bypass Vulnerability
nvd
CVE-2020-17040P3CRITICALCVSS 9.8≥ 10.0.0, < publication2020-11-11
CVE-2020-17040 [CRITICAL] CVE-2020-17040: Windows Hyper-V Security Feature Bypass Vulnerability
Windows Hyper-V Security Feature Bypass Vulnerability
nvd
CVE-2020-1285P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1285 [HIGH] CVE-2020-1285: <p>A remote code execution vulnerability exists in the way that the Windows Graphics Device Interfac
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users who
nvd
CVE-2020-1509P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1509 [HIGH] CVE-2020-1509: An elevation of privilege vulnerability exists in the Local Security Authority Subsystem Service (LS
An elevation of privilege vulnerability exists in the Local Security Authority Subsystem Service (LSASS) when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could cause an elevation of privilege on the target system's LSASS service.
The security update addresses the vul
nvd
CVE-2021-24091P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-02-25
CVE-2021-24091 [HIGH] CWE-787 CVE-2021-24091: Windows Camera Codec Pack Remote Code Execution Vulnerability
Windows Camera Codec Pack Remote Code Execution Vulnerability
nvd
CVE-2021-1694P3CRITICALCVSS 9.8≥ 10.0.0, < publication2021-01-12
CVE-2021-1694 [CRITICAL] CWE-269 CVE-2021-1694: Windows Update Stack Elevation of Privilege Vulnerability
Windows Update Stack Elevation of Privilege Vulnerability
nvd
CVE-2020-0922P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-09-11
CVE-2020-0922 [HIGH] CVE-2020-0922: <p>A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles ob
A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system.
To exploit the vulnerability, a user would have to open a specially crafted file or lure the target to a website hosting malicious JavaScript.
nvd
CVE-2020-1561P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1561 [HIGH] CVE-2020-1561: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system.
To exploit the vulnerability, a user would have to open a specially crafted file.
The security update addresses the vulnerability by correct
nvd
CVE-2020-1339P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1339 [HIGH] CVE-2020-1339: A remote code execution vulnerability exists when Windows Media Audio Codec improperly handles objec
A remote code execution vulnerability exists when Windows Media Audio Codec improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user
nvd
CVE-2020-1508P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1508 [HIGH] CVE-2020-1508: <p>A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles
A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user
nvd
CVE-2021-26867P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-03-11
CVE-2021-26867 [HIGH] CVE-2021-26867: Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2020-16915P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16915 [HIGH] CWE-787 CVE-2020-16915: <p>A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights.
There are multiple ways an attacker could exploit the vulnerability, such as by convinc
nvd
CVE-2021-26443P3CRITICALCVSS 9.0≥ 10.0.0, < 10.0.19041.13482021-11-10
CVE-2021-26443 [CRITICAL] CVE-2021-26443: Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
nvd
CVE-2021-34497P3HIGHCVSS 8.8≥ 10.0.0, < 10.0.19041.11102021-07-14
CVE-2021-34497 [HIGH] CVE-2021-34497: Windows MSHTML Platform Remote Code Execution Vulnerability
Windows MSHTML Platform Remote Code Execution Vulnerability
nvd
CVE-2021-40461P3CRITICALCVSS 9.0≥ 10.0.0, < 10.0.19041.12882021-10-13
CVE-2021-40461 [CRITICAL] CVE-2021-40461: Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2021-34447P3HIGHCVSS 8.8≥ 10.0.0, < 10.0.19041.11102021-07-16
CVE-2021-34447 [HIGH] CVE-2021-34447: Windows MSHTML Platform Remote Code Execution Vulnerability
Windows MSHTML Platform Remote Code Execution Vulnerability
nvd