Msrc Windows 10 Version 1703 For X64-Based Systems vulnerabilities

179 known vulnerabilities affecting msrc/windows_10_version_1703_for_x64-based_systems.

Total CVEs
179
CISA KEV
6
actively exploited
Public exploits
28
Exploited in wild
6
Severity breakdown
HIGH80MEDIUM96LOW3

Vulnerabilities

Page 1 of 9
CVE-2019-1340HIGHCVSS 7.82019-10-08
CVE-2019-1340 [HIGH] Microsoft Windows Elevation of Privilege Vulnerability Microsoft Windows Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The
msrc
CVE-2019-1321MEDIUMCVSS 5.82019-10-08
CVE-2019-1321 [HIGH] Microsoft Windows CloudStore Elevation of Privilege Vulnerability Microsoft Windows CloudStore Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when Windows CloudStore improperly handles file Discretionary Access Control List (DACL). An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. To exploit this vulnerability, an attacker would first have to log on to th
msrc
CVE-2019-1230MEDIUMCVSS 6.82019-10-08
CVE-2019-1230 [MEDIUM] Hyper-V Information Disclosure Vulnerability Hyper-V Information Disclosure Vulnerability Description: An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host operating system fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker on a guest operating system could run a specially crafted application that could cause the Hyper-V host operating system to disc
msrc
CVE-2019-1253HIGHCVSS 7.8KEVPoC2019-09-10
CVE-2019-1253 [HIGH] Windows Elevation of Privilege Vulnerability Windows Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correcting how AppX Deplo
msrc
CVE-2019-1277HIGHCVSS 7.82019-09-10
CVE-2019-1277 [HIGH] Windows Audio Service Elevation of Privilege Vulnerability Windows Audio Service Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in Windows Audio Service when a malformed parameter is processed. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges when used in conjunction with another vulnerability. To exploit the vulnerability, an attacker could run a specially crafted ap
msrc
CVE-2019-1303HIGHCVSS 7.82019-09-10
CVE-2019-1303 [HIGH] Windows Elevation of Privilege Vulnerability Windows Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correcting how AppX Deplo
msrc
CVE-2019-1251MEDIUMCVSS 5.52019-09-10
CVE-2019-1251 [MEDIUM] DirectWrite Information Disclosure Vulnerability DirectWrite Information Disclosure Vulnerability Description: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted doc
msrc
CVE-2019-0928MEDIUMCVSS 5.42019-09-10
CVE-2019-0928 [MEDIUM] Windows Hyper-V Denial of Service Vulnerability Windows Hyper-V Denial of Service Vulnerability Description: A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application that causes a host ma
msrc
CVE-2019-1216MEDIUMCVSS 5.52019-09-10
CVE-2019-1216 [MEDIUM] DirectX Information Disclosure Vulnerability DirectX Information Disclosure Vulnerability Description: An information disclosure vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. An authenticated attacker could exploit this vulnerability by running a specially crafted application. The update addresses the vulnerability by correc
msrc
CVE-2019-1254MEDIUMCVSS 5.52019-09-10
CVE-2019-1254 [MEDIUM] Windows Hyper-V Information Disclosure Vulnerability Windows Hyper-V Information Disclosure Vulnerability Description: An information disclosure vulnerability exists when Windows Hyper-V writes uninitialized memory to disk. An attacker could exploit the vulnerability by reading a file to recover kernel memory. To exploit the vulnerability, an attacker would first require access to a Hyper-V host. The security update addresses the vulnerability by ensuring Hyper-V properly
msrc
CVE-2019-0718MEDIUMCVSS 5.82019-08-13
CVE-2019-0718 [MEDIUM] Windows Hyper-V Denial of Service Vulnerability Windows Hyper-V Denial of Service Vulnerability Description: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. To exploit the vulnerability, an attacker who already has a privileged account on a guest o
msrc
CVE-2019-1171MEDIUMCVSS 5.62019-08-13
CVE-2019-1171 [MEDIUM] SymCrypt Information Disclosure Vulnerability SymCrypt Information Disclosure Vulnerability Description: An information disclosure vulnerability exists in SymCrypt during the OAEP decryption stage. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not
msrc
CVE-2019-1129HIGHCVSS 7.8KEV2019-07-09
CVE-2019-1129 [HIGH] Windows Elevation of Privilege Vulnerability Windows Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change or delete data. To exploit this vulnerability, an attacker would first have to log on to the s
msrc
CVE-2019-0865HIGHCVSS 7.52019-07-09
CVE-2019-0865 [HIGH] SymCrypt Denial of Service Vulnerability SymCrypt Denial of Service Vulnerability Description: A denial of service vulnerability exists when SymCrypt improperly handles a specially crafted digital signature. An attacker could exploit the vulnerability by creating a specially crafted connection or message. The security update addresses the vulnerability by correcting the way SymCrypt handles digital signatures. Microsoft Windows: Microsoft Windows Microsoft: Microsoft Imp
msrc
CVE-2019-0999HIGHCVSS 7.82019-07-09
CVE-2019-0999 [HIGH] DirectX Elevation of Privilege Vulnerability DirectX Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would first have t
msrc
CVE-2019-0966MEDIUMCVSS 6.82019-07-09
CVE-2019-0966 [MEDIUM] Windows Hyper-V Denial of Service Vulnerability Windows Hyper-V Denial of Service Vulnerability Description: A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application that causes a host ma
msrc
CVE-2019-1021HIGHCVSS 7.82019-06-11
CVE-2019-1021 [HIGH] Windows Audio Service Elevation of Privilege Vulnerability Windows Audio Service Elevation of Privilege Vulnerability Description: An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that could exploit the vulnerability. This vulnerability by itself does not allow arbitrary code
msrc
CVE-2019-1045HIGHCVSS 7.82019-06-11
CVE-2019-1045 [HIGH] Windows Network File System Elevation of Privilege Vulnerability Windows Network File System Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in the way that the Windows Network File System (NFS) handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application
msrc
CVE-2019-1018HIGHCVSS 7.02019-06-11
CVE-2019-1018 [HIGH] DirectX Elevation of Privilege Vulnerability DirectX Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would first have t
msrc
CVE-2019-0709HIGHCVSS 7.62019-06-11
CVE-2019-0709 [HIGH] Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary code.
msrc