Windows 10 version 1607
by Microsoft
CVEs (1,459)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-59506 | Hig | 0.46 | 7.0 | 0.00 | Nov 11, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-59289 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-59282 | Hig | 0.46 | 7.0 | 0.01 | Oct 14, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-59261 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-59208 | Hig | 0.46 | 7.1 | 0.01 | Oct 14, 2025 | Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-59205 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-59202 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-59196 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-59195 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to deny service locally. | ||
| CVE-2025-59194 | Hig | 0.46 | 7.0 | 0.03 | Oct 14, 2025 | Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-59193 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-58738 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-58736 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-58735 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-58734 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-58733 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-58732 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-58731 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-58730 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-58727 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. |
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.0epss 0.00
Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.1epss 0.01
Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to deny service locally.
- risk 0.46cvss 7.0epss 0.03
Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
Page 47 of 73