VendorsMicrosoftwindows_10_1507any version
Vulnerabilities

Microsoft Windows 10 1507 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1285CVEs
CVE-2017-0144
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.
Published 2017-03-17 · Analyzed
9.3KEV6 PoCEPSS 0.992
CVE-2017-0143
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.
Published 2017-03-17 · Analyzed
9.3KEV4 PoCEPSS 0.933
CVE-2017-0146
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0148.
Published 2017-03-17 · Analyzed
9.3KEV4 PoCEPSS 0.899
CVE-2017-0145
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0146, and CVE-2017-0148.
Published 2017-03-17 · Analyzed
9.3KEV3 PoCEPSS 0.899
CVE-2017-8759
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."
Published 2017-09-13 · Analyzed
9.3KEV1 PoCEPSS 0.887
CVE-2021-1675
Windows Print Spooler Remote Code Execution Vulnerability
Published 2021-06-08 · Analyzed
9.3KEVEPSS 0.853
CVE-2017-8540
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8538 and CVE-2017-8541.
Published 2017-05-26 · Analyzed
9.3KEV1 PoCEPSS 0.719
CVE-2016-3393
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Component RCE Vulnerability."
Published 2016-10-14 · Analyzed
9.3KEVEPSS 0.685
CVE-2016-7256
atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Open Type Font Remote Code Execution Vulnerability."
Published 2016-11-10 · Analyzed
9.3KEVEPSS 0.646
CVE-2019-0541
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.
Published 2019-01-08 · Analyzed
9.3KEV1 PoCEPSS 0.532
CVE-2015-2502
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2015.
Published 2015-08-19 · Analyzed
9.3KEVEPSS 0.510
CVE-2021-34448
Scripting Engine Memory Corruption Vulnerability
Published 2021-07-16 · Analyzed
9.3KEVEPSS 0.401
CVE-2021-31956
Windows NTFS Elevation of Privilege Vulnerability
Published 2021-06-08 · Analyzed
9.3KEVEPSS 0.223
CVE-2019-0903
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
Published 2019-05-16 · Analyzed
9.3KEVEPSS 0.217
CVE-2021-34527
Windows Print Spooler Remote Code Execution Vulnerability
Published 2021-07-02 · Analyzed
9.0KEVEPSS 0.998
CVE-2022-26923
Active Directory Domain Services Elevation of Privilege Vulnerability
Published 2022-05-10 · Analyzed
9.0KEVEPSS 0.835
CVE-2021-40444
Microsoft MSHTML Remote Code Execution Vulnerability
Published 2021-09-15 · Analyzed
8.8KEVEPSS 0.975
CVE-2023-36025
Windows SmartScreen Security Feature Bypass Vulnerability
Published 2023-11-14 · Analyzed
8.8KEVEPSS 0.881
CVE-2025-33053
Internet Shortcut Files Remote Code Execution Vulnerability
Published 2025-06-10 · Analyzed
8.8KEVEPSS 0.870
CVE-2016-7200
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.
Published 2016-11-10 · Analyzed
8.8KEV2 PoCEPSS 0.829
CVE-2025-33073
Windows SMB Client Elevation of Privilege Vulnerability
Published 2025-06-10 · Analyzed
8.8KEV1 PoCEPSS 0.827
CVE-2021-26411
Internet Explorer Memory Corruption Vulnerability
Published 2021-03-11 · Analyzed
8.8KEVEPSS 0.808
CVE-2016-7201
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7200, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.
Published 2016-11-10 · Analyzed
8.8KEV2 PoCEPSS 0.801
CVE-2018-0824
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-05-09 · Analyzed
8.8KEV1 PoCEPSS 0.732
CVE-2020-1020
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0938.
Published 2020-04-15 · Analyzed
8.8KEVEPSS 0.650
CVE-2021-33742
Windows MSHTML Platform Remote Code Execution Vulnerability
Published 2021-06-08 · Analyzed
8.8KEVEPSS 0.594
CVE-2024-43461
Windows MSHTML Platform Spoofing Vulnerability
Published 2024-09-10 · Analyzed
8.8KEVEPSS 0.545
CVE-2025-53778
Windows NTLM Elevation of Privilege Vulnerability
Published 2025-08-12 · Modified
8.8EPSS 0.476
CVE-2013-3900
WinVerifyTrust Signature Validation Vulnerability
Published 2013-12-11 · Analyzed
8.8KEVEPSS 0.446
CVE-2023-21674
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Published 2023-01-10 · Analyzed
8.8KEVEPSS 0.410
CVE-2024-38144
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
Published 2024-08-13 · Analyzed
8.8EPSS 0.323
CVE-2017-0222
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.
Published 2017-05-12 · Analyzed
8.8KEVEPSS 0.296
CVE-2017-0149
Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0018 and CVE-2017-0037.
Published 2017-03-17 · Analyzed
8.8KEVEPSS 0.292
CVE-2023-36017
Windows Scripting Engine Memory Corruption Vulnerability
Published 2023-11-14 · Modified
8.8EPSS 0.253
CVE-2022-41128
Windows Scripting Languages Remote Code Execution Vulnerability
Published 2022-11-09 · Analyzed
8.8KEVEPSS 0.246
CVE-2020-1380
Scripting Engine Memory Corruption Vulnerability
Published 2020-08-17 · Analyzed
8.8KEVEPSS 0.242
CVE-2017-0210
An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Internet Explorer Elevation of Privilege Vulnerability."
Published 2017-04-12 · Analyzed
8.8KEVEPSS 0.223
CVE-2025-54918
Windows NTLM Elevation of Privilege Vulnerability
Published 2025-09-09 · Analyzed
8.8EPSS 0.194
CVE-2025-21293
Active Directory Domain Services Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
8.8EPSS 0.190
CVE-2024-20674
Windows Kerberos Security Feature Bypass Vulnerability
Published 2024-01-09 · Modified
8.8EPSS 0.172
← Prev2 / 33Next →