Msrc Windows 10 Version 1809 vulnerabilities
3,423 known vulnerabilities affecting msrc/windows_10_version_1809.
Total CVEs
3,423
CISA KEV
131
actively exploited
Public exploits
95
Exploited in wild
118
Severity breakdown
CRITICAL59HIGH2451MEDIUM894LOW19
Vulnerabilities
Page 23 of 172
CVE-2025-33057MEDIUMCVSS 6.52025-06-10
CVE-2025-33057 [MEDIUM] CWE-476 Windows Local Security Authority (LSA) Denial of Service Vulnerability
Windows Local Security Authority (LSA) Denial of Service Vulnerability
Description: Null pointer dereference in Windows Local Security Authority (LSA) allows an authorized attacker to deny service over a network.
Windows Local Security Authority (LSA): Windows Local Security Authority (LSA)
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Public
msrc
CVE-2025-33052MEDIUMCVSS 5.52025-06-10
CVE-2025-33052 [MEDIUM] CWE-908 Windows DWM Core Library Information Disclosure Vulnerability
Windows DWM Core Library Information Disclosure Vulnerability
Description: Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized stack memory.
msrc
CVE-2025-33063MEDIUMCVSS 5.52025-06-10
CVE-2025-33063 [MEDIUM] CWE-125 Windows Storage Management Provider Information Disclosure Vulnerability
Windows Storage Management Provider Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
W
msrc
CVE-2025-3052MEDIUMCVSS 6.72025-06-10
CVE-2025-3052 [HIGH] CWE-822 Cert CC: CVE-2025-3052 InsydeH2O Secure Boot Bypass
Cert CC: CVE-2025-3052 InsydeH2O Secure Boot Bypass
Description: Untrusted pointer dereference in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could bypass Secure Boot.
FAQ: Why is this CERT/CC CVE included in the S
msrc
CVE-2025-32720MEDIUMCVSS 5.52025-06-10
CVE-2025-32720 [MEDIUM] CWE-125 Windows Storage Management Provider Information Disclosure Vulnerability
Windows Storage Management Provider Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
W
msrc
CVE-2025-33061MEDIUMCVSS 5.52025-06-10
CVE-2025-33061 [MEDIUM] CWE-125 Windows Storage Management Provider Information Disclosure Vulnerability
Windows Storage Management Provider Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
W
msrc
CVE-2025-33065MEDIUMCVSS 5.52025-06-10
CVE-2025-33065 [MEDIUM] CWE-125 Windows Storage Management Provider Information Disclosure Vulnerability
Windows Storage Management Provider Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
W
msrc
CVE-2025-33059MEDIUMCVSS 5.52025-06-10
CVE-2025-33059 [MEDIUM] CWE-125 Windows Storage Management Provider Information Disclosure Vulnerability
Windows Storage Management Provider Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
W
msrc
CVE-2025-47160MEDIUMCVSS 5.42025-06-10
CVE-2025-47160 [MEDIUM] CWE-693 Windows Shortcut Files Security Feature Bypass Vulnerability
Windows Shortcut Files Security Feature Bypass Vulnerability
Description: Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to no loss of confidentiality (C:N), but could lead to some loss of integrity (I:L) and availability (A:L). What do
msrc
CVE-2025-32715MEDIUMCVSS 6.52025-06-10
CVE-2025-32715 [MEDIUM] CWE-125 Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability
Description: Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
FAQ: According t
msrc
CVE-2025-33062MEDIUMCVSS 5.52025-06-10
CVE-2025-33062 [MEDIUM] CWE-125 Windows Storage Management Provider Information Disclosure Vulnerability
Windows Storage Management Provider Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
W
msrc
CVE-2025-29833HIGHCVSS 7.72025-05-13
CVE-2025-29833 [HIGH] CWE-367 Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
Description: Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to execute code locally.
FAQ: According to the CVSS metric, user interaction is required (UI:R) and privileges required is Low (PR:L). What does that mean for this vulnerability?
An authorized a
msrc
CVE-2025-29962HIGHCVSS 8.82025-05-13
CVE-2025-29962 [HIGH] CWE-122 Windows Media Remote Code Execution Vulnerability
Windows Media Remote Code Execution Vulnerability
Description: Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
FAQ: How could an attacker exploit this vulnerability?
An unauthenticated attacker who successfully exploited this vulnerability could gain code execution through convincing a user to open a malicious document at which point the attacker could exe
msrc
CVE-2025-24063HIGHCVSS 7.82025-05-13
CVE-2025-24063 [HIGH] CWE-122 Kernel Streaming Service Driver Elevation of Privilege Vulnerability
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
Description: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
FAQ: According to the C
msrc
CVE-2025-32701HIGHCVSS 7.8KEV2025-05-13
CVE-2025-32701 [HIGH] CWE-416 Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Description: Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
msrc
CVE-2025-32706HIGHCVSS 7.8KEV2025-05-13
CVE-2025-32706 [HIGH] CWE-20 Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Description: Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM pri
msrc
CVE-2025-30385HIGHCVSS 7.82025-05-13
CVE-2025-30385 [HIGH] CWE-416 Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Description: Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker who successfully exploited this vulnerability could potentially gain the abili
msrc
CVE-2025-29964HIGHCVSS 8.82025-05-13
CVE-2025-29964 [HIGH] CWE-122 Windows Media Remote Code Execution Vulnerability
Windows Media Remote Code Execution Vulnerability
Description: Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
FAQ: How could an attacker exploit this vulnerability?
An unauthenticated attacker who successfully exploited this vulnerability could gain code execution through convincing a user to open a malicious document at which point the attacker could exe
msrc
CVE-2025-32709HIGHCVSS 7.8KEV2025-05-13
CVE-2025-32709 [HIGH] CWE-416 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Description: Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker who successfully exploited this vulnerabilit
msrc
CVE-2025-30397HIGHCVSS 7.5KEVPoC2025-05-13
CVE-2025-30397 [HIGH] CWE-843 Scripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
Description: Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to first prepare
msrc