Msrc Windows 10 vulnerabilities
3,258 known vulnerabilities affecting msrc/windows_10.
Total CVEs
3,258
CISA KEV
135
actively exploited
Public exploits
194
Exploited in wild
131
Severity breakdown
CRITICAL60HIGH2217MEDIUM954LOW27
Vulnerabilities
Page 50 of 163
CVE-2023-35360HIGHCVSS 7.02023-07-11
CVE-2023-35360 [HIGH] CWE-591 Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an at
msrc
CVE-2023-35297HIGHCVSS 8.12023-07-11
CVE-2023-35297 [HIGH] CWE-843 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.
FAQ: According to the CVSS score, the attack
msrc
CVE-2023-36884HIGHCVSS 7.5KEV2023-07-11
CVE-2023-36884 [HIGH] CWE-362 Windows Search Remote Code Execution Vulnerability
Windows Search Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condition.
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to high loss of confidentiality (C:H), integrity (I:H) and availa
msrc
CVE-2023-35338HIGHCVSS 7.52023-07-11
CVE-2023-35338 [HIGH] CWE-476 Windows Peer Name Resolution Protocol Denial of Service Vulnerability
Windows Peer Name Resolution Protocol Denial of Service Vulnerability
Windows Peer Name Resolution Protocol: Windows Peer Name Resolution Protocol
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search
msrc
CVE-2023-35339HIGHCVSS 7.52023-07-11
CVE-2023-35339 [HIGH] CWE-400 Windows CryptoAPI Denial of Service Vulnerability
Windows CryptoAPI Denial of Service Vulnerability
Windows CryptoAPI: Windows CryptoAPI
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028168
Reference: https://support.microsoft.com/help/5028168
Refer
msrc
CVE-2023-35306MEDIUMCVSS 5.52023-07-11
CVE-2023-35306 [MEDIUM] CWE-20 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could view heap memory from a privileged process running on the server.
Microsoft Printer Drivers: Microsoft Printer Drivers
Microsoft: Microsoft
Customer Acti
msrc
CVE-2023-33172MEDIUMCVSS 6.52023-07-11
CVE-2023-33172 [MEDIUM] CWE-126 Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
Windows Remote Procedure Call: Windows Remote Procedure Call
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028168
Reference:
msrc
CVE-2023-32035MEDIUMCVSS 6.52023-07-11
CVE-2023-32035 [MEDIUM] CWE-125 Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
Windows Remote Procedure Call: Windows Remote Procedure Call
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028168
Reference:
msrc
CVE-2023-35314MEDIUMCVSS 6.52023-07-11
CVE-2023-35314 [MEDIUM] CWE-125 Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
Windows Remote Procedure Call: Windows Remote Procedure Call
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028168
Reference:
msrc
CVE-2023-32040MEDIUMCVSS 5.52023-07-11
CVE-2023-32040 [MEDIUM] CWE-822 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could view heap memory from a privileged process running on the server.
Microsoft Printer Drivers: Microsoft Printer Drivers
Microsoft: Microsoft
Customer Act
msrc
CVE-2023-35308MEDIUMCVSS 6.52023-07-11
CVE-2023-35308 [MEDIUM] CWE-73 Windows MSHTML Platform Security Feature Bypass Vulnerability
Windows MSHTML Platform Security Feature Bypass Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker must send the user a malicious file and convince them to open it.
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
A security feature bypass vulnerability exists wh
msrc
CVE-2023-35329MEDIUMCVSS 6.52023-07-11
CVE-2023-35329 [MEDIUM] CWE-400 Windows Authentication Denial of Service Vulnerability
Windows Authentication Denial of Service Vulnerability
Windows Authentication Methods: Windows Authentication Methods
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028168
Reference: https://supp
msrc
CVE-2023-33169MEDIUMCVSS 6.52023-07-11
CVE-2023-33169 [MEDIUM] CWE-126 Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
Windows Remote Procedure Call: Windows Remote Procedure Call
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028168
Reference:
msrc
CVE-2023-35318MEDIUMCVSS 6.52023-07-11
CVE-2023-35318 [MEDIUM] CWE-125 Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
Windows Remote Procedure Call: Windows Remote Procedure Call
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028168
Reference:
msrc
CVE-2023-35296MEDIUMCVSS 6.52023-07-11
CVE-2023-35296 [MEDIUM] CWE-125 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
Microsoft Printer Drivers: Microsoft Printer Drivers
Microsoft: Microsoft
Customer Action Required: Yes
msrc
CVE-2023-33164MEDIUMCVSS 6.52023-07-11
CVE-2023-33164 [MEDIUM] CWE-125 Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
Windows Remote Procedure Call: Windows Remote Procedure Call
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028168
Reference:
msrc
CVE-2023-35341MEDIUMCVSS 6.22023-07-11
CVE-2023-35341 [MEDIUM] CWE-190 Microsoft DirectMusic Information Disclosure Vulnerability
Microsoft DirectMusic Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
Windows Media: Windows Media
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Exploited:N
msrc
CVE-2023-33174MEDIUMCVSS 5.52023-07-11
CVE-2023-33174 [MEDIUM] CWE-200 Windows Cryptographic Information Disclosure Vulnerability
Windows Cryptographic Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
Windows Cryptographic Services: Windows Cryptographic Services
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Information Disclosure
Exploit Status:
msrc
CVE-2023-36871MEDIUMCVSS 6.52023-07-11
CVE-2023-36871 [MEDIUM] Azure Active Directory Security Feature Bypass Vulnerability
Azure Active Directory Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker can bypass Windows Trusted Platform Module by crafting an assertion and using the assertion to request a Primary Refresh Token from another device.
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean fo
msrc
CVE-2023-35336MEDIUMCVSS 6.52023-07-11
CVE-2023-35336 [MEDIUM] CWE-20 Windows MSHTML Platform Security Feature Bypass Vulnerability
Windows MSHTML Platform Security Feature Bypass Vulnerability
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L) and some loss of availability (A:L). What does that mean for this vulnerability?
An attacker who successfully exploits the vulnerability could craft a malicious URL that would evade zone checks, resulting in a limited lo
msrc