Windows 10 version 1607
by Microsoft
CVEs (1,387)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-43572 | Hig | 0.68 | 7.8 | 0.67 | KEV | Oct 8, 2024 | Microsoft Management Console Remote Code Execution Vulnerability | |
| CVE-2024-38193 | Hig | 0.68 | 7.8 | 0.27 | KEV | Aug 13, 2024 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
| CVE-2024-35250 | Hig | 0.68 | 7.8 | 0.25 | KEV | Jun 11, 2024 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | |
| CVE-2024-38112 | Hig | 0.67 | 7.5 | 0.84 | KEV | Jul 9, 2024 | Windows MSHTML Platform Spoofing Vulnerability | |
| CVE-2024-30080 | Cri | 0.67 | 9.8 | 0.43 | Jun 11, 2024 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||
| CVE-2025-21333 | Hig | 0.66 | 7.8 | 0.10 | KEV | Jan 14, 2025 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | |
| CVE-2025-47981 | Cri | 0.65 | 9.8 | 0.25 | Jul 8, 2025 | Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-30397 | Hig | 0.65 | 7.5 | 0.27 | KEV | May 13, 2025 | Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network. | |
| CVE-2023-36397 | Cri | 0.65 | 9.8 | 0.18 | Nov 14, 2023 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | ||
| CVE-2025-60724 | Cri | 0.64 | 9.8 | 0.06 | Nov 11, 2025 | Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-49708 | Cri | 0.64 | 9.9 | 0.01 | Oct 14, 2025 | Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-53766 | Cri | 0.64 | 9.8 | 0.07 | Aug 12, 2025 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-21307 | Cri | 0.64 | 9.8 | 0.02 | Jan 14, 2025 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | ||
| CVE-2024-38199 | Cri | 0.64 | 9.8 | 0.02 | Aug 13, 2024 | Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability | ||
| CVE-2024-38178 | Hig | 0.64 | 7.5 | 0.41 | KEV | Aug 13, 2024 | Scripting Engine Memory Corruption Vulnerability | |
| CVE-2024-38140 | Cri | 0.64 | 9.8 | 0.04 | Aug 13, 2024 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | ||
| CVE-2024-21351 | Hig | 0.64 | 7.6 | 0.30 | KEV | Feb 13, 2024 | Windows SmartScreen Security Feature Bypass Vulnerability | |
| CVE-2023-36036 | Hig | 0.64 | 7.8 | 0.17 | KEV | Nov 14, 2023 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | |
| CVE-2023-36033 | Hig | 0.64 | 7.8 | 0.12 | KEV | Nov 14, 2023 | Windows DWM Core Library Elevation of Privilege Vulnerability | |
| CVE-2023-36028 | Cri | 0.64 | 9.8 | 0.03 | Nov 14, 2023 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability |
- risk 0.68cvss 7.8epss 0.67
Microsoft Management Console Remote Code Execution Vulnerability
- risk 0.68cvss 7.8epss 0.27
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- risk 0.68cvss 7.8epss 0.25
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
- risk 0.67cvss 7.5epss 0.84
Windows MSHTML Platform Spoofing Vulnerability
- risk 0.67cvss 9.8epss 0.43
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- risk 0.66cvss 7.8epss 0.10
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
- risk 0.65cvss 9.8epss 0.25
Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.
- risk 0.65cvss 7.5epss 0.27
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
- risk 0.65cvss 9.8epss 0.18
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.06
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.9epss 0.01
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.8epss 0.07
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.02
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
- risk 0.64cvss 7.5epss 0.41
Scripting Engine Memory Corruption Vulnerability
- risk 0.64cvss 9.8epss 0.04
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
- risk 0.64cvss 7.6epss 0.30
Windows SmartScreen Security Feature Bypass Vulnerability
- risk 0.64cvss 7.8epss 0.17
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
- risk 0.64cvss 7.8epss 0.12
Windows DWM Core Library Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.03
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
Page 2 of 70