Msrc Windows 10 For X64-Based Systems vulnerabilities
256 known vulnerabilities affecting msrc/windows_10_for_x64-based_systems.
Total CVEs
256
CISA KEV
5
actively exploited
Public exploits
31
Exploited in wild
5
Severity breakdown
CRITICAL7HIGH123MEDIUM115LOW11
Vulnerabilities
Page 9 of 13
CVE-2017-0219MEDIUMCVSS 5.32017-06-13
CVE-2017-0219 [MEDIUM] Device Guard Code Integrity Policy Security Feature Bypass Vulnerability
Device Guard Code Integrity Policy Security Feature Bypass Vulnerability
Description: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session. An attacker who successfully exploited this vulnerability could inject code into a trusted PowerShell process to bypass the Device Guard Code Integrity policy on the
msrc
CVE-2017-8493MEDIUMCVSS 5.62017-06-13
CVE-2017-8493 [MEDIUM] Windows Security Feature Bypass Vulnerability
Windows Security Feature Bypass Vulnerability
Description: A security feature bypass vulnerability exists when Microsoft Windows fails to enforce case sensitivity for certain variable checks, which could allow an attacker to set variables that are either read-only or require authentication.
To exploit this vulnerability, an attacker could run a specially crafted application to bypass Unified Extensible Firmware Interface (UEFI
msrc
CVE-2017-8575MEDIUMCVSS 4.72017-06-13
CVE-2017-8575 [MEDIUM] Microsoft Graphics Component Information Disclosure Vulnerability
Microsoft Graphics Component Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when the Windows Graphics component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
An authenticated attacker could exploit this vulnerability by running a specially craf
msrc
CVE-2017-0218MEDIUMCVSS 5.32017-06-13
CVE-2017-0218 [MEDIUM] Device Guard Code Integrity Policy Security Feature Bypass Vulnerability
Device Guard Code Integrity Policy Security Feature Bypass Vulnerability
Description: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session. An attacker who successfully exploited this vulnerability could inject code into a trusted PowerShell process to bypass the Device Guard Code Integrity policy on the
msrc
CVE-2017-8474MEDIUMCVSS 4.72017-06-13
CVE-2017-8474 [MEDIUM] Windows Kernel Information Disclosure Vulnerability
Windows Kernel Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.
To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
The update addresses t
msrc
CVE-2017-0291LOWCVSS 3.62017-06-13
CVE-2017-0291 [HIGH] Windows PDF Remote Code Execution
Windows PDF Remote Code Execution
Description: A remote code execution vulnerability exists in Microsoft Windows if a user opens a specially crafted .pdf file. An attacker who successfully exploited the vulnerabilities could cause arbitrary code to execute in the context of the current user.
If a user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs;
msrc
CVE-2017-8460LOWCVSS 3.32017-06-13
CVE-2017-8460 [HIGH] Windows PDF Information Disclosure Vulnerability
Windows PDF Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists in Microsoft Windows when a user opens a specially crafted PDF file. An attacker who successfully exploited the vulnerability could read memory in the context of the current user.
To exploit the vulnerability, an attacker would have to trick the user into opening the PDF file.
The update addresses the vulnerability by
msrc
CVE-2017-0212HIGHCVSS 7.62017-05-09
CVE-2017-0212 [HIGH] Windows Hyper-V vSMB Elevation of Privilege Vulnerability
Windows Hyper-V vSMB Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly validate vSMB packet data. An attacker who successfully exploited these vulnerabilities could gain elevated privileges on a target operating system.
This vulnerability by itself does not allow arbitrary code to be run. However, this vulnerability
msrc
CVE-2017-0259MEDIUMCVSS 4.7PoC2017-05-09
CVE-2017-0259 [MEDIUM] Windows Kernel Information Disclosure Vulnerability
Windows Kernel Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.
To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
The update addresses t
msrc
CVE-2017-0181HIGHCVSS 7.62017-04-11
CVE-2017-0181 [HIGH] Hyper-V Remote Code Execution Vulnerability
Hyper-V Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary code.
msrc
CVE-2017-0189HIGHCVSS 7.82017-04-11
CVE-2017-0189 [HIGH] Win32k Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnera
msrc
CVE-2017-0162HIGHCVSS 7.62017-04-11
CVE-2017-0162 [HIGH] Hyper-V Remote Code Execution Vulnerability
Hyper-V Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary code.
msrc
CVE-2017-0163HIGHCVSS 7.62017-04-11
CVE-2017-0163 [HIGH] Hyper-V Remote Code Execution Vulnerability
Hyper-V Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary code.
msrc
CVE-2017-0180HIGHCVSS 7.62017-04-11
CVE-2017-0180 [HIGH] Hyper-V Remote Code Execution Vulnerability
Hyper-V Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary code.
msrc
CVE-2017-0185MEDIUMCVSS 5.82017-04-11
CVE-2017-0185 [MEDIUM] Windows Hyper-V Denial of Service Vulnerability
Windows Hyper-V Denial of Service Vulnerability
Description: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash.
To exploit the vulnerability, an attacker who already has a privileged account on a guest o
msrc
CVE-2017-0183MEDIUMCVSS 5.82017-04-11
CVE-2017-0183 [MEDIUM] Windows Hyper-V Denial of Service Vulnerability
Windows Hyper-V Denial of Service Vulnerability
Description: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash.
To exploit the vulnerability, an attacker who already has a privileged account on a guest o
msrc
CVE-2017-0211MEDIUMCVSS 5.0PoC2017-04-11
CVE-2017-0211 [MEDIUM] Windows OLE Elevation of Privilege Vulnerability
Windows OLE Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in Microsoft Windows OLE when it fails an integrity-level check.
An attacker who successfully exploited the vulnerability could allow an application with limited privileges on an affected system to execute code at a medium integrity level. The vulnerability by itself does not allow arbitrary code to be run, but can b
msrc
CVE-2017-0184MEDIUMCVSS 5.42017-04-11
CVE-2017-0184 [MEDIUM] Windows Hyper-V Denial of Service Vulnerability
Windows Hyper-V Denial of Service Vulnerability
Description: A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application that causes a host ma
msrc
CVE-2017-0165MEDIUMCVSS 6.6PoC2017-04-11
CVE-2017-0165 [HIGH] Windows Elevation of Privilege Vulnerability
Windows Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when Microsoft Windows fails to properly sanitize handles in memory.
An attacker who successfully exploited the vulnerability could run arbitrary code as System. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit the vulnerability, an attacker would f
msrc
CVE-2017-0178MEDIUMCVSS 5.42017-04-11
CVE-2017-0178 [MEDIUM] Windows Hyper-V Denial of Service Vulnerability
Windows Hyper-V Denial of Service Vulnerability
Description: A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application that causes a host ma
msrc