Msrc Windows 10 Version 1809 vulnerabilities
3,423 known vulnerabilities affecting msrc/windows_10_version_1809.
Total CVEs
3,423
CISA KEV
131
actively exploited
Public exploits
95
Exploited in wild
118
Severity breakdown
CRITICAL59HIGH2451MEDIUM894LOW19
Vulnerabilities
Page 7 of 172
CVE-2026-20862MEDIUMCVSS 5.52026-01-13
CVE-2026-20862 [MEDIUM] CWE-200 Windows Management Services Information Disclosure Vulnerability
Windows Management Services Information Disclosure Vulnerability
Description: Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read portions of proce
msrc
CVE-2026-20936MEDIUMCVSS 4.32026-01-13
CVE-2026-20936 [MEDIUM] CWE-125 Windows NDIS Information Disclosure Vulnerability
Windows NDIS Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.
FAQ: What type of information could be disclosed by this vulnerability?
Exploiting this vulnerability could allow the disclosure of certain kernel memory content.
Windows NDIS: Windows NDIS
Microsoft: Microsoft
Customer Action Required:
msrc
CVE-2026-20827MEDIUMCVSS 5.52026-01-13
CVE-2026-20827 [MEDIUM] CWE-200 Tablet Windows User Interface (TWINUI) Subsystem Information Disclosure Vulnerability
Tablet Windows User Interface (TWINUI) Subsystem Information Disclosure Vulnerability
Description: Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could
msrc
CVE-2025-64673HIGHCVSS 7.82025-12-09
CVE-2025-64673 [HIGH] CWE-284 Windows Storage VSP Driver Elevation of Privilege Vulnerability
Windows Storage VSP Driver Elevation of Privilege Vulnerability
Description: Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Storvsp.sys Driver: Storvsp.sys
msrc
CVE-2025-55233HIGHCVSS 7.82025-12-09
CVE-2025-55233 [HIGH] CWE-125 Windows Projected File System Elevation of Privilege Vulnerability
Windows Projected File System Elevation of Privilege Vulnerability
Description: Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Projected Fi
msrc
CVE-2025-59517HIGHCVSS 7.82025-12-09
CVE-2025-59517 [HIGH] CWE-284 Windows Storage VSP Driver Elevation of Privilege Vulnerability
Windows Storage VSP Driver Elevation of Privilege Vulnerability
Description: Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Storage VSP Driv
msrc
CVE-2025-64658HIGHCVSS 7.52025-12-09
CVE-2025-64658 [HIGH] CWE-362 Windows File Explorer Elevation of Privilege Vulnerability
Windows File Explorer Elevation of Privilege Vulnerability
Description: Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
For an attacker to exploit this vulnerability, the
msrc
CVE-2025-62571HIGHCVSS 7.82025-12-09
CVE-2025-62571 [HIGH] CWE-20 Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
Description: Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Installer: Windows Installer
Microsoft: M
msrc
CVE-2025-62455HIGHCVSS 7.82025-12-09
CVE-2025-62455 [HIGH] CWE-20 Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
Description: Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Messag
msrc
CVE-2025-62474HIGHCVSS 7.82025-12-09
CVE-2025-62474 [HIGH] CWE-284 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Description: Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SY
msrc
CVE-2025-62461HIGHCVSS 7.82025-12-09
CVE-2025-62461 [HIGH] CWE-126 Windows Projected File System Elevation of Privilege Vulnerability
Windows Projected File System Elevation of Privilege Vulnerability
Description: Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows
msrc
CVE-2025-62466HIGHCVSS 7.82025-12-09
CVE-2025-62466 [HIGH] CWE-476 Windows Client-Side Caching Elevation of Privilege Vulnerability
Windows Client-Side Caching Elevation of Privilege Vulnerability
Description: Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Window
msrc
CVE-2025-62221HIGHCVSS 7.8KEV2025-12-09
CVE-2025-62221 [HIGH] CWE-416 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Description: Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges
msrc
CVE-2025-62472HIGHCVSS 7.82025-12-09
CVE-2025-62472 [HIGH] CWE-908 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Description: Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could g
msrc
CVE-2025-64680HIGHCVSS 7.82025-12-09
CVE-2025-64680 [HIGH] CWE-122 Windows DWM Core Library Elevation of Privilege Vulnerability
Windows DWM Core Library Elevation of Privilege Vulnerability
Description: Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows DWM Core Library: W
msrc
CVE-2025-62549HIGHCVSS 8.82025-12-09
CVE-2025-62549 [HIGH] CWE-822 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Description: Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
FAQ: According to the CVSS metric, the attack vector is network (AV:N), user interaction is required (UI:R), and privileges required are no
msrc
CVE-2025-62573HIGHCVSS 7.02025-12-09
CVE-2025-62573 [HIGH] CWE-416 DirectX Graphics Kernel Elevation of Privilege Vulnerability
DirectX Graphics Kernel Elevation of Privilege Vulnerability
Description: Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condition.
FAQ: What privileges could b
msrc
CVE-2025-59516HIGHCVSS 7.82025-12-09
CVE-2025-59516 [HIGH] CWE-306 Windows Storage VSP Driver Elevation of Privilege Vulnerability
Windows Storage VSP Driver Elevation of Privilege Vulnerability
Description: Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Win
msrc
CVE-2025-62565HIGHCVSS 7.32025-12-09
CVE-2025-62565 [HIGH] CWE-416 Windows File Explorer Elevation of Privilege Vulnerability
Windows File Explorer Elevation of Privilege Vulnerability
Description: Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
FAQ: According to the CVSS metric, user interaction is r
msrc
CVE-2025-62470HIGHCVSS 7.82025-12-09
CVE-2025-62470 [HIGH] CWE-122 Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Description: Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM p
msrc