Windows 10 version 1607
by Microsoft
CVEs (1,387)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36011 | Hig | 0.51 | 7.8 | 0.01 | Dec 12, 2023 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2023-36005 | Hig | 0.51 | 7.5 | 0.24 | Dec 12, 2023 | Windows Telephony Server Elevation of Privilege Vulnerability | ||
| CVE-2023-35644 | Hig | 0.51 | 7.8 | 0.06 | Dec 12, 2023 | Windows Sysmain Service Elevation of Privilege Vulnerability | ||
| CVE-2023-35631 | Hig | 0.51 | 7.8 | 0.07 | Dec 12, 2023 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2023-21740 | Hig | 0.51 | 7.8 | 0.01 | Dec 12, 2023 | Windows Media Remote Code Execution Vulnerability | ||
| CVE-2023-36719 | Hig | 0.51 | 7.8 | 0.01 | Nov 14, 2023 | Microsoft Speech Application Programming Interface (SAPI) Elevation of Privilege Vulnerability | ||
| CVE-2023-36705 | Hig | 0.51 | 7.8 | 0.01 | Nov 14, 2023 | Windows Installer Elevation of Privilege Vulnerability | ||
| CVE-2023-36408 | Hig | 0.51 | 7.8 | 0.01 | Nov 14, 2023 | Windows Hyper-V Elevation of Privilege Vulnerability | ||
| CVE-2023-36407 | Hig | 0.51 | 7.8 | 0.02 | Nov 14, 2023 | Windows Hyper-V Elevation of Privilege Vulnerability | ||
| CVE-2023-36396 | Hig | 0.51 | 7.8 | 0.02 | Nov 14, 2023 | Windows Compressed Folder Remote Code Execution Vulnerability | ||
| CVE-2023-36393 | Hig | 0.51 | 7.8 | 0.01 | Nov 14, 2023 | Windows User Interface Application Core Remote Code Execution Vulnerability | ||
| CVE-2023-36047 | Hig | 0.51 | 7.8 | 0.01 | Nov 14, 2023 | Windows Authentication Elevation of Privilege Vulnerability | ||
| CVE-2018-0828 | Hig | 0.51 | 7.8 | 0.01 | Feb 15, 2018 | Windows 10 version 1607 and Windows Server 2016 allow an elevation of privilege vulnerability due to how the MultiPoint management account password is stored, aka "Windows Elevation of Privilege Vulnerability". | ||
| CVE-2026-20852 | Hig | 0.50 | 7.7 | 0.01 | Jan 13, 2026 | Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. | ||
| CVE-2026-20804 | Hig | 0.50 | 7.7 | 0.01 | Jan 13, 2026 | Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. | ||
| CVE-2025-59200 | Hig | 0.50 | 7.7 | 0.01 | Oct 14, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Client allows an unauthorized attacker to perform spoofing locally. | ||
| CVE-2025-53139 | Hig | 0.50 | 7.7 | 0.00 | Oct 14, 2025 | Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally. | ||
| CVE-2025-53722 | Hig | 0.50 | 7.5 | 0.18 | Aug 12, 2025 | Uncontrolled resource consumption in Windows Remote Desktop Services allows an unauthorized attacker to deny service over a network. | ||
| CVE-2025-47984 | Hig | 0.50 | 7.5 | 0.14 | Jul 8, 2025 | Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-29833 | Hig | 0.50 | 7.7 | 0.00 | May 13, 2025 | Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to execute code locally. |
- risk 0.51cvss 7.8epss 0.01
Win32k Elevation of Privilege Vulnerability
- risk 0.51cvss 7.5epss 0.24
Windows Telephony Server Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.06
Windows Sysmain Service Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.07
Win32k Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Media Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Speech Application Programming Interface (SAPI) Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Installer Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Hyper-V Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.02
Windows Hyper-V Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.02
Windows Compressed Folder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows User Interface Application Core Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Authentication Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows 10 version 1607 and Windows Server 2016 allow an elevation of privilege vulnerability due to how the MultiPoint management account password is stored, aka "Windows Elevation of Privilege Vulnerability".
- risk 0.50cvss 7.7epss 0.01
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
- risk 0.50cvss 7.7epss 0.01
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
- risk 0.50cvss 7.7epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Client allows an unauthorized attacker to perform spoofing locally.
- risk 0.50cvss 7.7epss 0.00
Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally.
- risk 0.50cvss 7.5epss 0.18
Uncontrolled resource consumption in Windows Remote Desktop Services allows an unauthorized attacker to deny service over a network.
- risk 0.50cvss 7.5epss 0.14
Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network.
- risk 0.50cvss 7.7epss 0.00
Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to execute code locally.
Page 35 of 70