Microsoft Windows 10 Version 2004 For X64-Based Systems vulnerabilities
113 known vulnerabilities affecting microsoft/windows_10_version_2004_for_x64-based_systems.
Total CVEs
113
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
HIGH86MEDIUM27
Vulnerabilities
Page 1 of 6
CVE-2020-0986P1HIGHCVSS 7.8KEVRansomwarevunspecified2020-06-09
CVE-2020-0986 [HIGH] CWE-787 CVE-2020-0986: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-1276, CVE-
nvd
CVE-2020-1375P2HIGHCVSS 7.8Exploitedvunspecified2020-07-14
CVE-2020-1375 [HIGH] CVE-2020-1375: An elevation of privilege vulnerability exists when Windows improperly handles COM object creation,
An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Server Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1206P2HIGHCVSS 7.5Exploitedvunspecified2020-06-09
CVE-2020-1206 [HIGH] CWE-908 CVE-2020-1206: An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 3.
An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Information Disclosure Vulnerability'.
nvd
CVE-2020-1313P2HIGHCVSS 7.8PoCvunspecified2020-06-09
CVE-2020-1313 [HIGH] CVE-2020-1313: An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improper
An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file operations, aka 'Windows Update Orchestrator Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1421P2HIGHCVSS 8.8vunspecified2020-07-14
CVE-2020-1421 [HIGH] CWE-843 CVE-2020-1421: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
nvd
CVE-2020-1300P2HIGHCVSS 8.8vunspecified2020-06-09
CVE-2020-1300 [HIGH] CVE-2020-1300: A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet
A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files.To exploit the vulnerability, an attacker would have to convince a user to either open a specially crafted cabinet file or spoof a network printer and trick a user into installing a malicious cabinet file disguised as a printer driver.The update addresses
nvd
CVE-2020-1301P2HIGHCVSS 8.8vunspecified2020-06-09
CVE-2020-1301 [HIGH] CVE-2020-1301: A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0 (SMBv1) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'.
nvd
CVE-2020-1436P2HIGHCVSS 8.8vunspecified2020-07-14
CVE-2020-1436 [HIGH] CWE-787 CVE-2020-1436: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Windows Font Library Remote Code Execution Vulnerability'.
nvd
CVE-2020-1281P3HIGHCVSS 8.8vunspecified2020-06-09
CVE-2020-1281 [HIGH] CWE-190 CVE-2020-1281: A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate u
A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.
nvd
CVE-2020-1299P3HIGHCVSS 8.8vunspecified2020-06-09
CVE-2020-1299 [HIGH] CVE-2020-1299: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
nvd
CVE-2020-1435P3HIGHCVSS 8.8vunspecified2020-07-14
CVE-2020-1435 [HIGH] CVE-2020-1435: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2020-1248P3HIGHCVSS 8.8vunspecified2020-06-09
CVE-2020-1248 [HIGH] CVE-2020-1248: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2020-1286P3HIGHCVSS 8.8vunspecified2020-06-09
CVE-2020-1286 [HIGH] CWE-20 CVE-2020-1286: A remote code execution vulnerability exists when the Windows Shell does not properly validate file
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the current user, aka 'Windows Shell Remote Code Execution Vulnerability'.
nvd
CVE-2020-1412P3HIGHCVSS 8.8vunspecified2020-07-14
CVE-2020-1412 [HIGH] CWE-269 CVE-2020-1412: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
nvd
CVE-2020-1374P3HIGHCVSS 7.5vunspecified2020-07-14
CVE-2020-1374 [HIGH] CVE-2020-1374: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.
nvd
CVE-2020-1408P3HIGHCVSS 8.8vunspecified2020-07-14
CVE-2020-1408 [HIGH] CWE-346 CVE-2020-1408: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'.
nvd
CVE-2020-1317P3HIGHCVSS 8.8vunspecified2020-06-09
CVE-2020-1317 [HIGH] CVE-2020-1317: An elevation of privilege vulnerability exists when Group Policy improperly checks access, aka 'Grou
An elevation of privilege vulnerability exists when Group Policy improperly checks access, aka 'Group Policy Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1400P3HIGHCVSS 7.8vunspecified2020-07-14
CVE-2020-1400 [HIGH] CWE-191 CVE-2020-1400: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1401, CVE-2020-1407.
nvd
CVE-2020-1255P3HIGHCVSS 8.8vunspecified2020-06-09
CVE-2020-1255 [HIGH] CVE-2020-1255: An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Serv
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1410P3HIGHCVSS 7.8vunspecified2020-07-14
CVE-2020-1410 [HIGH] CVE-2020-1410: A remote code execution vulnerability exists when Windows Address Book (WAB) improperly processes vc
A remote code execution vulnerability exists when Windows Address Book (WAB) improperly processes vcard files.To exploit the vulnerability, an attacker could send a malicious vcard that a victim opens using Windows Address Book (WAB), aka 'Windows Address Book Remote Code Execution Vulnerability'.
nvd
1 / 6Next →