VendorsMicrosoftwindows_101903
Vulnerabilities

Microsoft Windows 10 1903

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1239CVEs
CVE-2020-0730
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.
Published 2020-02-11 · Modified
7.1EPSS 0.009
CVE-2020-1204
An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'.
Published 2020-06-09 · Modified
7.1EPSS 0.008
CVE-2020-0936
An elevation of privilege vulnerability exists when a Windows scheduled task improperly handles file redirections, aka 'Windows Scheduled Task Elevation of Privilege Vulnerability'.
Published 2020-04-15 · Modified
7.1EPSS 0.008
CVE-2020-0942
An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0944, CVE-2020-1029.
Published 2020-04-15 · Modified
7.1EPSS 0.008
CVE-2020-1405
An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1372.
Published 2020-07-14 · Modified
7.1EPSS 0.008
CVE-2020-0854
An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'.
Published 2020-03-12 · Modified
7.1EPSS 0.008
CVE-2020-1461
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.
Published 2020-07-14 · Modified
7.1EPSS 0.007
CVE-2020-0785
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.
Published 2020-03-12 · Modified
7.1EPSS 0.007
CVE-2020-1002
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.
Published 2020-04-15 · Modified
7.1EPSS 0.007
CVE-2020-1364
A denial of service vulnerability exists in the way that the WalletService handles files, aka 'Windows WalletService Denial of Service Vulnerability'.
Published 2020-07-14 · Modified
7.1EPSS 0.007
CVE-2019-0707
An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it.To exploit the vulnerability, in a local attack scenario, an attacker could run a specially crafted application to elevate the attacker's privilege level, aka 'Windows NDIS Elevation of Privilege Vulnerability'.
Published 2019-05-16 · Modified
7.0EPSS 0.009
CVE-2019-0931
An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations, aka 'Windows Storage Service Elevation of Privilege Vulnerability'.
Published 2019-05-16 · Modified
7.0EPSS 0.009
CVE-2019-1178
Windows Elevation of Privilege Vulnerability
Published 2019-08-14 · Modified
7.0EPSS 0.008
CVE-2019-1179
Windows Elevation of Privilege Vulnerability
Published 2019-08-14 · Modified
7.0EPSS 0.008
CVE-2019-1180
Windows Elevation of Privilege Vulnerability
Published 2019-08-14 · Modified
7.0EPSS 0.008
CVE-2019-1037
An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.
Published 2019-07-15 · Modified
7.0EPSS 0.008
CVE-2019-1173
Windows Elevation of Privilege Vulnerability
Published 2019-08-14 · Modified
7.0EPSS 0.007
CVE-2019-1186
Windows Elevation of Privilege Vulnerability
Published 2019-08-14 · Modified
7.0EPSS 0.007
CVE-2019-1174
Windows Elevation of Privilege Vulnerability
Published 2019-08-14 · Modified
7.0EPSS 0.007
CVE-2019-1175
Windows Elevation of Privilege Vulnerability
Published 2019-08-14 · Modified
7.0EPSS 0.007
CVE-2019-1177
Windows Elevation of Privilege Vulnerability
Published 2019-08-14 · Modified
7.0EPSS 0.007
CVE-2019-1416
An elevation of privilege vulnerability exists due to a race condition in Windows Subsystem for Linux, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'.
Published 2019-11-12 · Modified
7.0EPSS 0.005
CVE-2019-0972
Local Security Authority Subsystem Service Denial of Service Vulnerability
Published 2019-06-12 · Modified
6.8EPSS 0.058
CVE-2019-0712
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1309, CVE-2019-1310, CVE-2019-1399.
Published 2019-11-12 · Modified
6.8EPSS 0.056
CVE-2019-1309
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0712, CVE-2019-1310, CVE-2019-1399.
Published 2019-11-12 · Modified
6.8EPSS 0.055
CVE-2019-1310
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0712, CVE-2019-1309, CVE-2019-1399.
Published 2019-11-12 · Modified
6.8EPSS 0.055
CVE-2020-0993
A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries, aka 'Windows DNS Denial of Service Vulnerability'.
Published 2020-04-15 · Modified
6.8EPSS 0.052
CVE-2019-1292
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.
Published 2019-09-11 · Modified
6.8EPSS 0.051
CVE-2019-0716
Windows Denial of Service Vulnerability
Published 2019-08-14 · Modified
6.8EPSS 0.044
CVE-2019-0886
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.
Published 2019-05-16 · Modified
6.8EPSS 0.017
CVE-2019-0966
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'.
Published 2019-07-15 · Modified
6.8EPSS 0.016
CVE-2020-1398
An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly handle Ease of Access dialog.An attacker who successfully exploited the vulnerability could execute commands with elevated permissions.The security update addresses the vulnerability by ensuring that the Ease of Access dialog is handled properly., aka 'Windows Lockscreen Elevation of Privilege Vulnerability'.
Published 2020-07-14 · Modified
6.8EPSS 0.012
CVE-2020-0689
A security feature bypass vulnerability exists in secure boot, aka 'Microsoft Secure Boot Security Feature Bypass Vulnerability'.
Published 2020-02-11 · Modified
6.7EPSS 0.011
CVE-2020-1333
An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improperly handle reparse points, aka 'Group Policy Services Policy Processing Elevation of Privilege Vulnerability'.
Published 2020-07-14 · Modified
6.7EPSS 0.009
CVE-2019-1439
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
Published 2019-11-12 · Modified
6.5EPSS 0.754
CVE-2019-1252
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1286.
Published 2019-09-11 · Modified
6.5EPSS 0.604
CVE-2019-1245
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1244, CVE-2019-1251.
Published 2019-09-11 · Modified
6.51 PoCEPSS 0.129
CVE-2019-0758
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0882, CVE-2019-0961.
Published 2019-05-16 · Modified
6.5EPSS 0.123
CVE-2019-1244
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1245, CVE-2019-1251.
Published 2019-09-11 · Modified
6.51 PoCEPSS 0.121
CVE-2019-1108
An information disclosure vulnerability exists when the Windows RDP client improperly discloses the contents of its memory, aka 'Remote Desktop Protocol Client Information Disclosure Vulnerability'.
Published 2019-07-29 · Modified
6.5EPSS 0.107
← Prev25 / 31Next →