Msrc Windows 10 vulnerabilities
3,258 known vulnerabilities affecting msrc/windows_10.
Total CVEs
3,258
CISA KEV
135
actively exploited
Public exploits
194
Exploited in wild
131
Severity breakdown
CRITICAL60HIGH2217MEDIUM954LOW27
Vulnerabilities
Page 30 of 163
CVE-2024-38118MEDIUMCVSS 5.52024-08-13
CVE-2024-38118 [MEDIUM] CWE-908 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of stack memory.
FAQ: Windows 11, version 24H2 is not generally available yet. Why are there updates for this version of Windows
msrc
CVE-2024-38213MEDIUMCVSS 6.5KEV2024-08-13
CVE-2024-38213 [MEDIUM] CWE-693 Windows Mark of the Web Security Feature Bypass Vulnerability
Windows Mark of the Web Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could bypass the SmartScreen user experience.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker must send
msrc
CVE-2024-38143MEDIUMCVSS 4.22024-08-13
CVE-2024-38143 [MEDIUM] CWE-306 Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability
Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability
FAQ: How could an attacker exploit this vulnerability?
An unauthenticated attacker could exploit the vulnerability by interacting with a malicious wireless network from the lock screen of a device. Successful exploitation of this vulnerability does not crash systems or allow unauthorized access. However, it can potentially leak
msrc
CVE-2024-38069HIGHCVSS 7.02024-07-09
CVE-2024-38069 [HIGH] CWE-347 Windows Enroll Engine Security Feature Bypass Vulnerability
Windows Enroll Engine Security Feature Bypass Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to gather information specific to the environment and take additional actions prior to exploitation to prepare the target environment.
FAQ: What kind of security fe
msrc
CVE-2024-38034HIGHCVSS 7.82024-07-09
CVE-2024-38034 [HIGH] CWE-190 Windows Filtering Platform Elevation of Privilege Vulnerability
Windows Filtering Platform Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker who successfully exploited this vulnerability could gain administrator privileges.
Windows Filtering: Windows Filtering
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly
msrc
CVE-2024-38085HIGHCVSS 7.82024-07-09
CVE-2024-38085 [HIGH] CWE-416 Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Win32 Kernel Subsystem: Windows Win32 Kernel Subsystem
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Expl
msrc
CVE-2024-38053HIGHCVSS 8.82024-07-09
CVE-2024-38053 [HIGH] CWE-416 Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability
Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability
FAQ: According to the CVSS score, the attack vector is adjacent (AV:A). What does this mean for this vulnerability?
This attack is limited to systems connected to the same network segment as the attacker. The attack cannot be performed across multiple networks (for example, a WAN) and would be limited to systems on the
msrc
CVE-2024-37988HIGHCVSS 8.02024-07-09
CVE-2024-37988 [HIGH] CWE-130 Secure Boot Security Feature Bypass Vulnerability
Secure Boot Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could bypass Secure Boot.
FAQ: According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability?
An unauthenticated attacker with LAN access could exploit this vuln
msrc
CVE-2024-37987HIGHCVSS 8.02024-07-09
CVE-2024-37987 [HIGH] CWE-843 Secure Boot Security Feature Bypass Vulnerability
Secure Boot Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could bypass Secure Boot.
FAQ: According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability?
An unauthenticated attacker with LAN access could exploit this vuln
msrc
CVE-2024-30079HIGHCVSS 7.82024-07-09
CVE-2024-30079 [HIGH] CWE-126 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Remote Access Connection Manager: Windows Remote Access Connection Manager
Microsoft: Microsoft
Customer Action Req
msrc
CVE-2024-38057HIGHCVSS 7.82024-07-09
CVE-2024-38057 [HIGH] CWE-125 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Microsoft Streaming Service: Microsoft Streaming Service
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elev
msrc
CVE-2024-38070HIGHCVSS 7.82024-07-09
CVE-2024-38070 [HIGH] CWE-693 Windows LockDown Policy (WLDP) Security Feature Bypass Vulnerability
Windows LockDown Policy (WLDP) Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could bypass the execution policy for the Windows LockDown Policy (WLDP) for the WDAC API.
Windows LockDown Policy (WLDP): Windows LockDown Policy (WLDP)
Microsoft: Micros
msrc
CVE-2024-37986HIGHCVSS 8.02024-07-09
CVE-2024-37986 [HIGH] CWE-191 Secure Boot Security Feature Bypass Vulnerability
Secure Boot Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could bypass Secure Boot.
FAQ: According to the CVSS metric, user interaction is required (UI:R) and privileges required are none (PR:N). What does that mean for this vulnerability?
An unauthorized attacker mus
msrc
CVE-2024-38091HIGHCVSS 7.52024-07-09
CVE-2024-38091 [HIGH] CWE-166 Microsoft WS-Discovery Denial of Service Vulnerability
Microsoft WS-Discovery Denial of Service Vulnerability
Microsoft WS-Discovery: Microsoft WS-Discovery
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5040430
Reference: https://support.microsoft.com/help/504
msrc
CVE-2024-38061HIGHCVSS 7.52024-07-09
CVE-2024-38061 [HIGH] CWE-284 DCOM Remote Cross-Session Activation Elevation of Privilege Vulnerability
DCOM Remote Cross-Session Activation Elevation of Privilege Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.
FAQ: What privileges could be gained by an attacker
msrc
CVE-2024-28899HIGHCVSS 8.82024-07-09
CVE-2024-28899 [HIGH] CWE-121 Secure Boot Security Feature Bypass Vulnerability
Secure Boot Security Feature Bypass Vulnerability
FAQ: According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability?
An authenticated attacker could exploit this vulnerability with LAN access.
FAQ: How could an attacker successfully exploit this vulnerability?
To exploit the vulnerability, an attacker who has physical access or Administrative rights to a target devi
msrc
CVE-2024-30098HIGHCVSS 7.52024-07-09
CVE-2024-30098 [HIGH] CWE-327 Windows Cryptographic Services Security Feature Bypass Vulnerability
Windows Cryptographic Services Security Feature Bypass Vulnerability
FAQ: Are there any further actions I need to take to be protected from this vulnerability?
Yes. The Windows Smart Card infrastructure relies on the Cryptographic Service Provider (CSP) and Key Storage Provider (KSP) to isolate cryptographic operations from the Smart Card implementation. The KSP is part of the Crypto Next Generati
msrc
CVE-2024-38011HIGHCVSS 8.02024-07-09
CVE-2024-38011 [HIGH] CWE-130 Secure Boot Security Feature Bypass Vulnerability
Secure Boot Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could bypass Secure Boot.
FAQ: According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability?
An unauthenticated attacker with LAN access could exploit this vuln
msrc
CVE-2024-38079HIGHCVSS 7.82024-07-09
CVE-2024-38079 [HIGH] CWE-122 Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
FAQ: How could an attacker exploit this vulnerability?
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker c
msrc
CVE-2024-3596HIGHCVSS 7.52024-07-09
CVE-2024-3596 [CRITICAL] CWE-327 CERT/CC: CVE-2024-3596 RADIUS Protocol Spoofing Vulnerability
CERT/CC: CVE-2024-3596 RADIUS Protocol Spoofing Vulnerability
FAQ: Why is this CERT/CC CVE included in the Security Update Guide?
A vulnerability exists in the RADIUS protocol that potentially affects many products and implementations of the RFC 2865 in the UDP version of the RADIUS protocol. In brief, RADIUS protocol (RFC 2865) is susceptible to forgery attacks that can modify Access-Accept or Access
msrc