VendorsMicrosoftwindows_101607
Vulnerabilities

Microsoft Windows 10 1607

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2793CVEs
CVE-2022-26809
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
10.0EPSS 0.910
CVE-2019-1181
Remote Desktop Services Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
10.0EPSS 0.758
CVE-2017-11771
The Microsoft Windows Search component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly handle DNS responses, aka "Windows Search Remote Code Execution Vulnerability".
Published 2017-10-13 · Modified
10.0EPSS 0.641
CVE-2016-7182
The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Console allows attackers to execute arbitrary code via a crafted True Type font, aka "True Type Font Parsing Elevation of Privilege Vulnerability."
Published 2016-10-14 · Modified
10.01 PoCEPSS 0.303
CVE-2018-8421
A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 2.0.
Published 2018-09-13 · Modified
10.0EPSS 0.291
CVE-2017-8589
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way that Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability".
Published 2017-07-11 · Modified
10.0EPSS 0.262
CVE-2018-8540
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 4.6.2.
Published 2018-12-12 · Modified
10.0EPSS 0.216
CVE-2018-8626
A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly handle requests, aka "Windows DNS Server Heap Overflow Vulnerability." This affects Windows Server 2012 R2, Windows Server 2019, Windows Server 2016, Windows 10, Windows 10 Servers.
Published 2018-12-12 · Modified
10.0EPSS 0.212
CVE-2019-1182
Remote Desktop Services Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
10.0EPSS 0.168
CVE-2020-0690
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.
Published 2020-03-12 · Modified
10.0EPSS 0.070
CVE-2016-3270
The Graphics component in the kernel in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
Published 2016-10-14 · Modified
10.0EPSS 0.066
CVE-2016-3266
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3376, CVE-2016-7185, and CVE-2016-7211.
Published 2016-10-14 · Modified
10.0EPSS 0.062
CVE-2020-1467
Windows Hard Link Elevation of Privilege Vulnerability
Published 2020-08-17 · Modified
10.0EPSS 0.035
CVE-2022-21874
Windows Security Center API Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
10.0EPSS 0.023
CVE-2021-26424
Windows TCP/IP Remote Code Execution Vulnerability
Published 2021-08-12 · Modified
9.9EPSS 0.611
CVE-2021-28476
Windows Hyper-V Remote Code Execution Vulnerability
Published 2021-05-11 · Modified
9.9EPSS 0.386
CVE-2019-1384
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an attacker could send a specially crafted authentication request, aka 'Microsoft Windows Security Feature Bypass Vulnerability'.
Published 2019-11-12 · Modified
9.9EPSS 0.076
CVE-2020-17095
Windows Hyper-V Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
9.9EPSS 0.050
CVE-2019-1365
An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the context of NT AUTHORITY\system escaping the Sandbox.The security update addresses the vulnerability by correcting how Microsoft IIS Server sanitizes web requests., aka 'Microsoft IIS Server Elevation of Privilege Vulnerability'.
Published 2019-10-10 · Modified
9.9EPSS 0.044
CVE-2020-1112
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
Published 2020-05-21 · Modified
9.9EPSS 0.033
CVE-2022-34721
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
9.8EPSS 0.789
CVE-2019-0626
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
Published 2019-03-06 · Modified
9.8EPSS 0.686
CVE-2022-34718
Windows TCP/IP Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
9.8EPSS 0.544
CVE-2021-34481
Windows Print Spooler Remote Code Execution Vulnerability
Published 2021-07-16 · Modified
9.8EPSS 0.477
CVE-2022-24497
Windows Network File System Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.8EPSS 0.346
CVE-2022-24491
Windows Network File System Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.8EPSS 0.335
CVE-2021-24074
Windows TCP/IP Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
9.8EPSS 0.257
CVE-2021-24094
Windows TCP/IP Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
9.8EPSS 0.221
CVE-2021-26432
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
Published 2021-08-12 · Modified
9.8EPSS 0.113
CVE-2021-36936
Windows Print Spooler Remote Code Execution Vulnerability
Published 2021-08-12 · Modified
9.8EPSS 0.074
CVE-2019-1212
Windows DHCP Server Denial of Service Vulnerability
Published 2019-08-14 · Modified
9.8EPSS 0.067
CVE-2021-43217
Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
Published 2021-12-15 · Modified
9.8EPSS 0.064
CVE-2022-21849
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.8EPSS 0.062
CVE-2017-11899
Device Guard in Windows 10 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerability due to the way untrusted files are handled, aka "Microsoft Windows Security Feature Bypass Vulnerability".
Published 2017-12-12 · Modified
9.8EPSS 0.058
CVE-2021-36965
Windows WLAN AutoConfig Service Remote Code Execution Vulnerability
Published 2021-09-15 · Modified
9.8EPSS 0.046
CVE-2022-22012
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.8EPSS 0.040
CVE-2019-0736
Windows DHCP Client Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
9.8EPSS 0.040
CVE-2021-31962
Kerberos AppContainer Security Feature Bypass Vulnerability
Published 2021-06-08 · Modified
9.8EPSS 0.038
CVE-2022-29130
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.8EPSS 0.038
CVE-2021-1694
Windows Update Stack Elevation of Privilege Vulnerability
Published 2021-01-12 · Modified
9.8EPSS 0.032
1 / 70Next →