Windows 10 version 1607
by Microsoft
CVEs (1,459)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-33053 | Hig | 0.79 | 8.8 | 0.87 | KEV | Jun 10, 2025 | External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network. | |
| CVE-2024-21412 | Hig | 0.78 | 8.1 | 0.99 | KEV | Feb 13, 2024 | Internet Shortcut Files Security Feature Bypass Vulnerability | |
| CVE-2025-33073 | Hig | 0.77 | 8.8 | 0.83 | KEV | Jun 10, 2025 | Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. | |
| CVE-2024-49039 | Hig | 0.76 | 8.8 | 0.14 | KEV | Nov 12, 2024 | Windows Task Scheduler Elevation of Privilege Vulnerability | |
| CVE-2024-21338 | Hig | 0.76 | 7.8 | 0.60 | KEV | Feb 13, 2024 | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2023-36025 | Hig | 0.76 | 8.8 | 0.88 | KEV | Nov 14, 2023 | Windows SmartScreen Security Feature Bypass Vulnerability | |
| CVE-2024-43461 | Hig | 0.73 | 8.8 | 0.54 | KEV | Sep 10, 2024 | Windows MSHTML Platform Spoofing Vulnerability | |
| CVE-2024-29988 | Hig | 0.73 | 8.8 | 0.45 | KEV | Apr 9, 2024 | SmartScreen Prompt Security Feature Bypass Vulnerability | |
| CVE-2026-21510 | Hig | 0.71 | 8.8 | 0.24 | KEV | Feb 10, 2026 | Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. | |
| CVE-2026-21513 | Hig | 0.70 | 8.8 | 0.16 | KEV | Feb 10, 2026 | Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network. | |
| CVE-2025-29824 | Hig | 0.70 | 7.8 | 0.14 | KEV | Apr 8, 2025 | Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | |
| CVE-2025-21298 | Cri | 0.70 | 9.8 | 0.81 | Jan 14, 2025 | Windows OLE Remote Code Execution Vulnerability | ||
| CVE-2024-30040 | Hig | 0.70 | 8.8 | 0.04 | KEV | May 14, 2024 | Windows MSHTML Platform Security Feature Bypass Vulnerability | |
| CVE-2025-26633 | Hig | 0.69 | 7.0 | 0.30 | KEV | Mar 11, 2025 | Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. | |
| CVE-2024-49112 | Cri | 0.69 | 9.8 | 0.72 | Dec 12, 2024 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | ||
| CVE-2024-38063 | Cri | 0.69 | 9.8 | 0.71 | Aug 13, 2024 | Windows TCP/IP Remote Code Execution Vulnerability | ||
| CVE-2024-30088 | Hig | 0.69 | 7.0 | 0.68 | KEV | Jun 11, 2024 | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2024-30051 | Hig | 0.69 | 7.8 | 0.06 | KEV | May 14, 2024 | Windows DWM Core Library Elevation of Privilege Vulnerability | |
| CVE-2024-26169 | Hig | 0.69 | 7.8 | 0.04 | KEV | Mar 12, 2024 | Windows Error Reporting Service Elevation of Privilege Vulnerability | |
| CVE-2019-1069 | Hig | 0.69 | 7.8 | 0.06 | KEV | Jun 12, 2019 | An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an attacker would… |
- risk 0.79cvss 8.8epss 0.87
External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.
- risk 0.78cvss 8.1epss 0.99
Internet Shortcut Files Security Feature Bypass Vulnerability
- risk 0.77cvss 8.8epss 0.83
Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
- risk 0.76cvss 8.8epss 0.14
Windows Task Scheduler Elevation of Privilege Vulnerability
- risk 0.76cvss 7.8epss 0.60
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.76cvss 8.8epss 0.88
Windows SmartScreen Security Feature Bypass Vulnerability
- risk 0.73cvss 8.8epss 0.54
Windows MSHTML Platform Spoofing Vulnerability
- risk 0.73cvss 8.8epss 0.45
SmartScreen Prompt Security Feature Bypass Vulnerability
- risk 0.71cvss 8.8epss 0.24
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.70cvss 8.8epss 0.16
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.70cvss 7.8epss 0.14
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
- risk 0.70cvss 9.8epss 0.81
Windows OLE Remote Code Execution Vulnerability
- risk 0.70cvss 8.8epss 0.04
Windows MSHTML Platform Security Feature Bypass Vulnerability
- risk 0.69cvss 7.0epss 0.30
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
- risk 0.69cvss 9.8epss 0.72
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- risk 0.69cvss 9.8epss 0.71
Windows TCP/IP Remote Code Execution Vulnerability
- risk 0.69cvss 7.0epss 0.68
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.69cvss 7.8epss 0.06
Windows DWM Core Library Elevation of Privilege Vulnerability
- risk 0.69cvss 7.8epss 0.04
Windows Error Reporting Service Elevation of Privilege Vulnerability
- risk 0.69cvss 7.8epss 0.06
An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an attacker would…
Page 1 of 73