VendorsMicrosoftwindows_101803
Vulnerabilities

Microsoft Windows 10 1803

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1790CVEs
CVE-2020-0914
Windows State Repository Service Information Disclosure Vulnerability
Published 2020-09-11 · Modified
5.5EPSS 0.011
CVE-2019-0942
An elevation of privilege vulnerability exists in the Unified Write Filter (UWF) feature for Windows 10 when it improperly restricts access to the registry, aka 'Unified Write Filter Elevation of Privilege Vulnerability'.
Published 2019-05-16 · Modified
5.5EPSS 0.010
CVE-2019-1142
An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) allows file creation in arbitrary locations, aka '.NET Framework Elevation of Privilege Vulnerability'.
Published 2019-09-11 · Modified
5.5EPSS 0.010
CVE-2020-0779
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0798, CVE-2020-0814, CVE-2020-0842, CVE-2020-0843.
Published 2020-03-12 · Modified
5.5EPSS 0.010
CVE-2021-24107
Windows Event Tracing Information Disclosure Vulnerability
Published 2021-03-11 · Modified
5.5EPSS 0.010
CVE-2021-26869
Windows ActiveX Installer Service Information Disclosure Vulnerability
Published 2021-03-11 · Modified
5.5EPSS 0.010
CVE-2021-26884
Windows Media Photo Codec Information Disclosure Vulnerability
Published 2021-03-11 · Modified
5.5EPSS 0.010
CVE-2021-24076
Microsoft Windows VMSwitch Information Disclosure Vulnerability
Published 2021-02-25 · Modified
5.5EPSS 0.009
CVE-2021-24079
Windows Backup Engine Information Disclosure Vulnerability
Published 2021-02-25 · Modified
5.5EPSS 0.009
CVE-2021-24106
Windows DirectX Information Disclosure Vulnerability
Published 2021-02-25 · Modified
5.5EPSS 0.009
CVE-2020-0989
Windows Mobile Device Management Diagnostics Information Disclosure Vulnerability
Published 2020-09-11 · Modified
5.5EPSS 0.009
CVE-2019-1270
An elevation of privilege vulnerability exists in Windows store installer where WindowsApps directory is vulnerable to symbolic link attack, aka 'Microsoft Windows Store Installer Elevation of Privilege Vulnerability'.
Published 2019-09-11 · Modified
5.5EPSS 0.009
CVE-2021-1731
PFX Encryption Security Feature Bypass Vulnerability
Published 2021-02-25 · Modified
5.5EPSS 0.009
CVE-2020-16922
Windows Spoofing Vulnerability
Published 2020-10-16 · Modified
5.5EPSS 0.008
CVE-2021-28309
Windows Kernel Information Disclosure Vulnerability
Published 2021-04-13 · Modified
5.5EPSS 0.008
CVE-2021-27093
Windows Kernel Information Disclosure Vulnerability
Published 2021-04-13 · Modified
5.5EPSS 0.008
CVE-2021-28317
Microsoft Windows Codecs Library Information Disclosure Vulnerability
Published 2021-04-13 · Modified
5.5EPSS 0.008
CVE-2021-31191
Windows Projected File System FS Filter Driver Information Disclosure Vulnerability
Published 2021-05-11 · Modified
5.5EPSS 0.008
CVE-2021-28479
Windows CSC Service Information Disclosure Vulnerability
Published 2021-05-11 · Modified
5.5EPSS 0.008
CVE-2021-28437
Windows Installer Information Disclosure Vulnerability
Published 2021-04-13 · Modified
5.5EPSS 0.008
CVE-2021-28435
Windows Event Tracing Information Disclosure Vulnerability
Published 2021-04-13 · Modified
5.5EPSS 0.008
CVE-2021-28318
Windows GDI+ Information Disclosure Vulnerability
Published 2021-04-13 · Modified
5.5EPSS 0.008
CVE-2018-8356
A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, ASP.NET Core 1.1, Microsoft .NET Framework 4.5.2, ASP.NET Core 2.0, ASP.NET Core 1.0, .NET Core 1.1, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 1.0, .NET Core 2.0, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.
Published 2018-07-11 · Modified
5.5EPSS 0.007
CVE-2019-1289
An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does not properly enforce file share permissions, aka 'Windows Update Delivery Optimization Elevation of Privilege Vulnerability'.
Published 2019-09-11 · Modified
5.5EPSS 0.007
CVE-2021-28438
Windows Console Driver Denial of Service Vulnerability
Published 2021-04-13 · Modified
5.5EPSS 0.007
CVE-2021-28443
Windows Console Driver Denial of Service Vulnerability
Published 2021-04-13 · Modified
5.5EPSS 0.006
CVE-2019-1454
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.
Published 2020-01-24 · Modified
5.5EPSS 0.006
CVE-2018-8434
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-09-13 · Modified
5.4EPSS 0.035
CVE-2018-8547
A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Federation Services (AD FS) does not properly sanitize a specially crafted web request to an affected AD FS server, aka "Active Directory Federation Services XSS Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
Published 2018-11-14 · Modified
5.4EPSS 0.016
CVE-2019-1273
A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize certain error messages, aka 'Active Directory Federation Services XSS Vulnerability'.
Published 2019-09-11 · Modified
5.4EPSS 0.015
CVE-2020-1596
TLS Information Disclosure Vulnerability
Published 2020-09-11 · Modified
5.4EPSS 0.009
CVE-2019-0612
A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash objects. By itself, this bypass vulnerability does not allow arbitrary code execution, aka 'Microsoft Edge Security Feature Bypass Vulnerability'.
Published 2019-04-08 · Modified
5.31 PoCEPSS 0.105
CVE-2019-1324
An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles IPv6 flowlabel filled in packets, aka 'Windows TCP/IP Information Disclosure Vulnerability'.
Published 2019-11-12 · Modified
5.3EPSS 0.046
CVE-2020-1242
An information disclosure vulnerability exists in the way that Microsoft Edge handles cross-origin requests, aka 'Microsoft Edge Information Disclosure Vulnerability'.
Published 2020-06-09 · Modified
5.3EPSS 0.038
CVE-2020-1315
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory, aka 'Internet Explorer Information Disclosure Vulnerability'.
Published 2020-06-09 · Modified
5.3EPSS 0.038
CVE-2018-8212
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8201, CVE-2018-8211, CVE-2018-8215, CVE-2018-8216, CVE-2018-8217, CVE-2018-8221.
Published 2018-06-14 · Modified
5.3EPSS 0.022
CVE-2018-8211
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID is unique from CVE-2018-8201, CVE-2018-8212, CVE-2018-8215, CVE-2018-8216, CVE-2018-8217, CVE-2018-8221.
Published 2018-06-14 · Modified
5.3EPSS 0.021
CVE-2018-8215
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8201, CVE-2018-8211, CVE-2018-8212, CVE-2018-8216, CVE-2018-8217, CVE-2018-8221.
Published 2018-06-14 · Modified
5.3EPSS 0.021
CVE-2018-8221
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8201, CVE-2018-8211, CVE-2018-8212, CVE-2018-8215, CVE-2018-8216, CVE-2018-8217.
Published 2018-06-14 · Modified
5.3EPSS 0.021
CVE-2018-8222
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
Published 2018-07-11 · Modified
5.3EPSS 0.021
← Prev43 / 45Next →