Windows 10 version 1607
by Microsoft
CVEs (1,387)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-26248 | Hig | 0.49 | 7.5 | 0.01 | Apr 9, 2024 | Windows Kerberos Elevation of Privilege Vulnerability | ||
| CVE-2024-26219 | Hig | 0.49 | 7.5 | 0.03 | Apr 9, 2024 | HTTP.sys Denial of Service Vulnerability | ||
| CVE-2024-26190 | Hig | 0.49 | 7.5 | 0.03 | Mar 12, 2024 | Microsoft QUIC Denial of Service Vulnerability | ||
| CVE-2024-21438 | Hig | 0.49 | 7.5 | 0.03 | Mar 12, 2024 | Microsoft AllJoyn API Denial of Service Vulnerability | ||
| CVE-2024-21406 | Hig | 0.49 | 7.5 | 0.01 | Feb 13, 2024 | Windows Printing Service Spoofing Vulnerability | ||
| CVE-2024-21348 | Hig | 0.49 | 7.5 | 0.02 | Feb 13, 2024 | Internet Connection Sharing (ICS) Denial of Service Vulnerability | ||
| CVE-2024-21347 | Hig | 0.49 | 7.5 | 0.01 | Feb 13, 2024 | Microsoft ODBC Driver Remote Code Execution Vulnerability | ||
| CVE-2024-21342 | Hig | 0.49 | 7.5 | 0.03 | Feb 13, 2024 | Windows DNS Client Denial of Service Vulnerability | ||
| CVE-2024-21307 | Hig | 0.49 | 7.5 | 0.02 | Jan 9, 2024 | Remote Desktop Client Remote Code Execution Vulnerability | ||
| CVE-2024-20700 | Hig | 0.49 | 7.5 | 0.04 | Jan 9, 2024 | Windows Hyper-V Remote Code Execution Vulnerability | ||
| CVE-2024-20687 | Hig | 0.49 | 7.5 | 0.03 | Jan 9, 2024 | Microsoft AllJoyn API Denial of Service Vulnerability | ||
| CVE-2024-20661 | Hig | 0.49 | 7.5 | 0.03 | Jan 9, 2024 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2023-36004 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2023 | Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability | ||
| CVE-2026-21235 | Hig | 0.48 | 7.3 | 0.01 | Feb 10, 2026 | Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20853 | Hig | 0.48 | 7.4 | 0.00 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-20844 | Hig | 0.48 | 7.4 | 0.00 | Jan 13, 2026 | Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-20805 | Med | 0.48 | 5.5 | 0.05 | KEV | Jan 13, 2026 | Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. | |
| CVE-2025-55687 | Hig | 0.48 | 7.4 | 0.00 | Oct 14, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File System (ReFS) allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2025-55335 | Hig | 0.48 | 7.4 | 0.00 | Oct 14, 2025 | Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2025-48004 | Hig | 0.48 | 7.4 | 0.02 | Oct 14, 2025 | Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. |
- risk 0.49cvss 7.5epss 0.01
Windows Kerberos Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.03
HTTP.sys Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Microsoft QUIC Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Microsoft AllJoyn API Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
Windows Printing Service Spoofing Vulnerability
- risk 0.49cvss 7.5epss 0.02
Internet Connection Sharing (ICS) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
Microsoft ODBC Driver Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows DNS Client Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Remote Desktop Client Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.04
Windows Hyper-V Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.03
Microsoft AllJoyn API Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability
- risk 0.48cvss 7.3epss 0.01
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- risk 0.48cvss 7.4epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate privileges locally.
- risk 0.48cvss 7.4epss 0.00
Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.
- risk 0.48cvss 5.5epss 0.05
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
- risk 0.48cvss 7.4epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File System (ReFS) allows an unauthorized attacker to elevate privileges locally.
- risk 0.48cvss 7.4epss 0.00
Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
- risk 0.48cvss 7.4epss 0.02
Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
Page 40 of 70