VendorsMicrosoftwindows_101709
Vulnerabilities

Microsoft Windows 10 1709

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1679CVEs
CVE-2020-1420
An information disclosure vulnerability exists when Windows Error Reporting improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Error Reporting Information Disclosure Vulnerability'.
Published 2020-07-14 · Modified
5.5EPSS 0.012
CVE-2020-1386
An information vulnerability exists when Windows Connected User Experiences and Telemetry Service improperly discloses file information, aka 'Connected User Experiences and Telemetry Service Information Disclosure Vulnerability'.
Published 2020-07-14 · Modified
5.5EPSS 0.012
CVE-2020-1389
An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1367, CVE-2020-1419, CVE-2020-1426.
Published 2020-07-14 · Modified
5.5EPSS 0.012
CVE-2020-1038
Windows Routing Utilities Denial of Service
Published 2020-09-11 · Modified
5.5EPSS 0.012
CVE-2020-16854
Windows Kernel Information Disclosure Vulnerability
Published 2020-09-11 · Modified
5.5EPSS 0.012
CVE-2018-8549
A security feature bypass exists when Windows incorrectly validates kernel driver signatures, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
Published 2018-11-14 · Modified
5.5EPSS 0.012
CVE-2020-1033
Windows Kernel Information Disclosure Vulnerability
Published 2020-09-11 · Modified
5.5EPSS 0.012
CVE-2020-0941
Win32k Information Disclosure Vulnerability
Published 2020-09-11 · Modified
5.5EPSS 0.011
CVE-2020-1383
Windows RRAS Service Information Disclosure Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.011
CVE-2020-1485
Windows Image Acquisition Service Information Disclosure Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.011
CVE-2020-1476
ASP.NET and .NET Elevation of Privilege Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.011
CVE-2020-1076
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.
Published 2020-05-21 · Modified
5.5EPSS 0.011
CVE-2020-1084
A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values.An attacker who successfully exploited this vulnerability could deny dependent security feature functionality.To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.The security update addresses the vulnerability by correcting how the Connected User Experiences and Telemetry Service validates certain function values., aka 'Connected User Experiences and Telemetry Service Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-1123.
Published 2020-05-21 · Modified
5.5EPSS 0.011
CVE-2020-1123
A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-1084.
Published 2020-05-21 · Modified
5.5EPSS 0.011
CVE-2020-0914
Windows State Repository Service Information Disclosure Vulnerability
Published 2020-09-11 · Modified
5.5EPSS 0.011
CVE-2020-0921
Microsoft Graphics Component Denial of Service Vulnerability
Published 2020-09-11 · Modified
5.5EPSS 0.011
CVE-2020-1083
Microsoft Graphics Component Information Disclosure Vulnerability
Published 2020-09-11 · Modified
5.5EPSS 0.011
CVE-2020-1250
Win32k Information Disclosure Vulnerability
Published 2020-09-11 · Modified
5.5EPSS 0.011
CVE-2019-0942
An elevation of privilege vulnerability exists in the Unified Write Filter (UWF) feature for Windows 10 when it improperly restricts access to the registry, aka 'Unified Write Filter Elevation of Privilege Vulnerability'.
Published 2019-05-16 · Modified
5.5EPSS 0.010
CVE-2019-1142
An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) allows file creation in arbitrary locations, aka '.NET Framework Elevation of Privilege Vulnerability'.
Published 2019-09-11 · Modified
5.5EPSS 0.010
CVE-2020-0779
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0798, CVE-2020-0814, CVE-2020-0842, CVE-2020-0843.
Published 2020-03-12 · Modified
5.5EPSS 0.010
CVE-2020-0989
Windows Mobile Device Management Diagnostics Information Disclosure Vulnerability
Published 2020-09-11 · Modified
5.5EPSS 0.009
CVE-2019-1270
An elevation of privilege vulnerability exists in Windows store installer where WindowsApps directory is vulnerable to symbolic link attack, aka 'Microsoft Windows Store Installer Elevation of Privilege Vulnerability'.
Published 2019-09-11 · Modified
5.5EPSS 0.009
CVE-2020-16922
Windows Spoofing Vulnerability
Published 2020-10-16 · Modified
5.5EPSS 0.008
CVE-2018-8356
A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, ASP.NET Core 1.1, Microsoft .NET Framework 4.5.2, ASP.NET Core 2.0, ASP.NET Core 1.0, .NET Core 1.1, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 1.0, .NET Core 2.0, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.
Published 2018-07-11 · Modified
5.5EPSS 0.007
CVE-2019-1289
An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does not properly enforce file share permissions, aka 'Windows Update Delivery Optimization Elevation of Privilege Vulnerability'.
Published 2019-09-11 · Modified
5.5EPSS 0.007
CVE-2019-1454
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.
Published 2020-01-24 · Modified
5.5EPSS 0.006
CVE-2018-1040
A denial of service vulnerability exists in the way that the Windows Code Integrity Module performs hashing, aka "Windows Code Integrity Module Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-06-14 · Modified
5.4EPSS 0.073
CVE-2018-8434
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-09-13 · Modified
5.4EPSS 0.035
CVE-2018-8547
A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Federation Services (AD FS) does not properly sanitize a specially crafted web request to an affected AD FS server, aka "Active Directory Federation Services XSS Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
Published 2018-11-14 · Modified
5.4EPSS 0.016
CVE-2020-1596
TLS Information Disclosure Vulnerability
Published 2020-09-11 · Modified
5.4EPSS 0.009
CVE-2018-0767
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0780 and CVE-2018-0800.
Published 2018-01-04 · Modified
5.31 PoCEPSS 0.655
CVE-2018-0780
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0767 and CVE-2018-0800.
Published 2018-01-04 · Modified
5.31 PoCEPSS 0.586
CVE-2017-11906
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how Internet Explorer handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11887 and CVE-2017-11919.
Published 2017-12-12 · Modified
5.31 PoCEPSS 0.251
CVE-2017-11834
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11791.
Published 2017-11-15 · Modified
5.3EPSS 0.127
CVE-2019-0612
A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash objects. By itself, this bypass vulnerability does not allow arbitrary code execution, aka 'Microsoft Edge Security Feature Bypass Vulnerability'.
Published 2019-04-08 · Modified
5.31 PoCEPSS 0.105
CVE-2018-1000
An information disclosure vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Information Disclosure Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0981, CVE-2018-0987, CVE-2018-0989.
Published 2018-04-12 · Modified
5.3EPSS 0.075
CVE-2018-0800
Microsoft Edge in Microsoft Windows 10 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0767 and CVE-2018-0780.
Published 2018-01-04 · Modified
5.3EPSS 0.067
CVE-2017-11887
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how Internet Explorer handle objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11906 and CVE-2017-11919.
Published 2017-12-12 · Modified
5.3EPSS 0.064
CVE-2018-0981
An information disclosure vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Information Disclosure Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0987, CVE-2018-0989, CVE-2018-1000.
Published 2018-04-12 · Modified
5.3EPSS 0.064
← Prev39 / 42Next →