VendorsMicrosoftwindows_101607
Vulnerabilities

Microsoft Windows 10 1607

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2793CVEs
CVE-2022-38021
Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
Published 2022-10-11 · Modified
7.0EPSS 0.004
CVE-2022-23283
Windows ALPC Elevation of Privilege Vulnerability
Published 2022-03-09 · Modified
7.0EPSS 0.004
CVE-2022-24505
Windows ALPC Elevation of Privilege Vulnerability
Published 2022-03-09 · Modified
7.0EPSS 0.004
CVE-2022-26807
Windows Work Folder Service Elevation of Privilege Vulnerability
Published 2022-04-15 · Modified
7.0EPSS 0.003
CVE-2022-24482
Windows ALPC Elevation of Privilege Vulnerability
Published 2022-04-15 · Modified
7.0EPSS 0.003
CVE-2022-21928
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
6.9EPSS 0.007
CVE-2022-22023
Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability
Published 2022-07-12 · Modified
6.9EPSS 0.006
CVE-2016-7237
Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote authenticated users to cause a denial of service (system hang) via a crafted request, aka "Local Security Authority Subsystem Service Denial of Service Vulnerability."
Published 2016-11-10 · Modified
6.81 PoCEPSS 0.669
CVE-2018-8438
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8436, CVE-2018-8437.
Published 2018-09-13 · Modified
6.8EPSS 0.072
CVE-2017-8623
Windows Hyper-V in Windows 10 1607, 1703, and Windows Server 2016 allows a denial of service vulnerability when it fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service Vulnerability".
Published 2017-08-08 · Modified
6.8EPSS 0.065
CVE-2019-0678
An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacker could host a website that is used to attempt to exploit the vulnerability, aka 'Microsoft Edge Elevation of Privilege Vulnerability'.
Published 2019-04-08 · Modified
6.8EPSS 0.061
CVE-2019-0972
Local Security Authority Subsystem Service Denial of Service Vulnerability
Published 2019-06-12 · Modified
6.8EPSS 0.058
CVE-2019-0712
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1309, CVE-2019-1310, CVE-2019-1399.
Published 2019-11-12 · Modified
6.8EPSS 0.056
CVE-2020-0993
A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries, aka 'Windows DNS Denial of Service Vulnerability'.
Published 2020-04-15 · Modified
6.8EPSS 0.052
CVE-2019-1292
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.
Published 2019-09-11 · Modified
6.8EPSS 0.051
CVE-2019-0716
Windows Denial of Service Vulnerability
Published 2019-08-14 · Modified
6.8EPSS 0.044
CVE-2018-8307
A security feature bypass vulnerability exists when Microsoft WordPad improperly handles embedded OLE objects, aka "WordPad Security Feature Bypass Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-07-11 · Modified
6.8EPSS 0.037
CVE-2021-43216
Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
Published 2021-12-15 · Modified
6.8EPSS 0.032
CVE-2017-8628
Microsoft Bluetooth Driver in Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703 allows a spoofing vulnerability due to Microsoft's implementation of the Bluetooth stack, aka "Microsoft Bluetooth Driver Spoofing Vulnerability".
Published 2017-09-13 · Modified
6.8EPSS 0.023
CVE-2019-0690
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0695, CVE-2019-0701.
Published 2019-04-08 · Modified
6.8EPSS 0.019
CVE-2019-0695
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0690, CVE-2019-0701.
Published 2019-04-08 · Modified
6.8EPSS 0.019
CVE-2019-0710
Windows Hyper-V Denial of Service Vulnerability
Published 2019-06-12 · Modified
6.8EPSS 0.019
CVE-2019-0711
Windows Hyper-V Denial of Service Vulnerability
Published 2019-06-12 · Modified
6.8EPSS 0.019
CVE-2019-0713
Windows Hyper-V Denial of Service Vulnerability
Published 2019-06-12 · Modified
6.8EPSS 0.019
CVE-2019-0886
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.
Published 2019-05-16 · Modified
6.8EPSS 0.017
CVE-2019-0966
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'.
Published 2019-07-15 · Modified
6.8EPSS 0.016
CVE-2020-0661
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-0751.
Published 2020-02-11 · Modified
6.8EPSS 0.016
CVE-2020-1398
An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly handle Ease of Access dialog.An attacker who successfully exploited the vulnerability could execute commands with elevated permissions.The security update addresses the vulnerability by ensuring that the Ease of Access dialog is handled properly., aka 'Windows Lockscreen Elevation of Privilege Vulnerability'.
Published 2020-07-14 · Modified
6.8EPSS 0.012
CVE-2020-17099
Windows Lock Screen Security Feature Bypass Vulnerability
Published 2020-12-09 · Modified
6.8EPSS 0.010
CVE-2022-44682
Windows Hyper-V Denial of Service Vulnerability
Published 2022-12-13 · Modified
6.8EPSS 0.007
CVE-2021-42274
Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability
Published 2021-11-10 · Modified
6.8EPSS 0.007
CVE-2020-0689
A security feature bypass vulnerability exists in secure boot, aka 'Microsoft Secure Boot Security Feature Bypass Vulnerability'.
Published 2020-02-11 · Modified
6.7EPSS 0.011
CVE-2022-34302
A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.
Published 2022-08-26 · Modified
6.7EPSS 0.011
CVE-2022-34301
A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.
Published 2022-08-26 · Modified
6.7EPSS 0.010
CVE-2020-1333
An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improperly handle reparse points, aka 'Group Policy Services Policy Processing Elevation of Privilege Vulnerability'.
Published 2020-07-14 · Modified
6.7EPSS 0.009
CVE-2022-34303
A flaw was found in Eurosoft bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.
Published 2022-08-26 · Modified
6.7EPSS 0.008
CVE-2021-34493
Windows Partition Management Driver Elevation of Privilege Vulnerability
Published 2021-07-14 · Modified
6.7EPSS 0.006
CVE-2022-30205
Windows Group Policy Elevation of Privilege Vulnerability
Published 2022-07-12 · Modified
6.6EPSS 0.012
CVE-2022-22048
BitLocker Security Feature Bypass Vulnerability
Published 2022-07-12 · Modified
6.6EPSS 0.008
CVE-2022-38032
Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability
Published 2022-10-11 · Modified
6.6EPSS 0.006
← Prev52 / 70Next →