VendorsMicrosoftwindows_10all versions
Vulnerabilities

Microsoft Windows 10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4056CVEs
CVE-2020-0936
An elevation of privilege vulnerability exists when a Windows scheduled task improperly handles file redirections, aka 'Windows Scheduled Task Elevation of Privilege Vulnerability'.
Published 2020-04-15 · Modified
7.1EPSS 0.008
CVE-2022-30226
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2022-07-12 · Modified
7.1EPSS 0.008
CVE-2022-22022
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2022-07-12 · Modified
7.1EPSS 0.008
CVE-2021-28446
Windows Portmapping Information Disclosure Vulnerability
Published 2021-04-13 · Modified
7.1EPSS 0.008
CVE-2020-1405
An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1372.
Published 2020-07-14 · Modified
7.1EPSS 0.008
CVE-2020-0854
An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'.
Published 2020-03-12 · Modified
7.1EPSS 0.008
CVE-2020-1461
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.
Published 2020-07-14 · Modified
7.1EPSS 0.007
CVE-2020-0785
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.
Published 2020-03-12 · Modified
7.1EPSS 0.007
CVE-2020-1002
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.
Published 2020-04-15 · Modified
7.1EPSS 0.007
CVE-2020-1364
A denial of service vulnerability exists in the way that the WalletService handles files, aka 'Windows WalletService Denial of Service Vulnerability'.
Published 2020-07-14 · Modified
7.1EPSS 0.007
CVE-2022-34690
Windows Fax Service Elevation of Privilege Vulnerability
Published 2022-08-09 · Modified
7.1EPSS 0.006
CVE-2022-30225
Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability
Published 2022-07-12 · Modified
7.1EPSS 0.006
CVE-2023-21760
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.1EPSS 0.005
CVE-2020-12899
Arbitrary Read in AMD Graphics Driver for Windows 10 may lead to KASLR bypass or denial of service.
Published 2021-11-15 · Modified
7.1EPSS 0.002
CVE-2020-12894
Arbitrary Write in AMD Graphics Driver for Windows 10 in Escape 0x40010d may lead to arbitrary write to kernel memory or denial of service.
Published 2021-11-15 · Modified
7.1EPSS 0.002
CVE-2018-0744
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Elevation of Privilege Vulnerability".
Published 2018-01-04 · Modified
7.01 PoCEPSS 0.150
CVE-2017-0277
The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0272, CVE-2017-0278, and CVE-2017-0279.
Published 2017-05-12 · Modified
7.0EPSS 0.109
CVE-2017-0278
The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0272, CVE-2017-0277, and CVE-2017-0279.
Published 2017-05-12 · Modified
7.0EPSS 0.109
CVE-2017-0279
The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0272, CVE-2017-0277, and CVE-2017-0278.
Published 2017-05-12 · Modified
7.0EPSS 0.109
CVE-2017-11780
The Server Message Block 1.0 (SMBv1) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows a remote code execution vulnerability when it fails to properly handle certain requests, aka "Windows SMB Remote Code Execution Vulnerability".
Published 2017-10-13 · Modified
7.0EPSS 0.100
CVE-2022-34725
Windows ALPC Elevation of Privilege Vulnerability
Published 2022-09-13 · Modified
7.0EPSS 0.054
CVE-2022-44673
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Published 2022-12-13 · Modified
7.0EPSS 0.052
CVE-2022-29142
Windows Kernel Elevation of Privilege Vulnerability
Published 2022-05-10 · Modified
7.0EPSS 0.051
CVE-2022-23279
Windows ALPC Elevation of Privilege Vulnerability
Published 2022-05-10 · Modified
7.0EPSS 0.047
CVE-2022-30202
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Published 2022-07-12 · Modified
7.0EPSS 0.045
CVE-2022-23286
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Published 2022-03-09 · Modified
7.0EPSS 0.043
CVE-2017-0214
Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when Windows fails to properly validate input before loading type libraries, aka "Windows COM Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-0213.
Published 2017-05-12 · Modified
7.01 PoCEPSS 0.035
CVE-2018-8214
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8208.
Published 2018-06-14 · Modified
7.01 PoCEPSS 0.033
CVE-2018-8208
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8214.
Published 2018-06-14 · Modified
7.01 PoCEPSS 0.032
CVE-2018-0826
Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Storage Services Elevation of Privilege Vulnerability".
Published 2018-02-15 · Modified
7.01 PoCEPSS 0.031
CVE-2018-0880
The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how the virtual registry is managed, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0882.
Published 2018-03-14 · Modified
7.01 PoCEPSS 0.031
CVE-2018-8134
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
Published 2018-05-09 · Modified
7.01 PoCEPSS 0.030
CVE-2018-0743
Windows Subsystem for Linux in Windows 10 version 1703, Windows 10 version 1709, and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Subsystem for Linux Elevation of Privilege Vulnerability".
Published 2018-01-04 · Modified
7.01 PoCEPSS 0.028
CVE-2018-0882
The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how the virtual registry is managed, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0880.
Published 2018-03-14 · Modified
7.01 PoCEPSS 0.028
CVE-2018-0823
The Named Pipe File System in Windows 10 version 1709 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way the Named Pipe File System handles objects, aka "Named Pipe File System Elevation of Privilege Vulnerability".
Published 2018-02-15 · Modified
7.01 PoCEPSS 0.026
CVE-2018-0822
NTFS in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way NTFS handles objects, aka "Windows NTFS Global Reparse Point Elevation of Privilege Vulnerability".
Published 2018-02-15 · Modified
7.01 PoCEPSS 0.026
CVE-2018-0982
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
Published 2018-06-14 · Modified
7.01 PoCEPSS 0.026
CVE-2017-11783
Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability in the way it handles calls to Advanced Local Procedure Call (ALPC), aka "Windows Elevation of Privilege Vulnerability".
Published 2017-10-13 · Modified
7.0EPSS 0.025
CVE-2018-0821
AppContainer in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way constrained impersonations are handled, aka "Windows AppContainer Elevation Of Privilege Vulnerability".
Published 2018-02-15 · Modified
7.01 PoCEPSS 0.023
CVE-2018-8333
An Elevation of Privilege vulnerability exists in Filter Manager when it improperly handles objects in memory, aka "Microsoft Filter Manager Elevation Of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-10-10 · Modified
7.0EPSS 0.019
← Prev74 / 102Next →