Windows 10 version 1607
by Microsoft
CVEs (1,459)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-38060 | Hig | 0.58 | 8.8 | 0.16 | Jul 9, 2024 | Windows Imaging Component Remote Code Execution Vulnerability | ||
| CVE-2024-30078 | Hig | 0.58 | 8.8 | 0.05 | Jun 11, 2024 | Windows Wi-Fi Driver Remote Code Execution Vulnerability | ||
| CVE-2023-35641 | Hig | 0.58 | 8.8 | 0.07 | Dec 12, 2023 | Internet Connection Sharing (ICS) Remote Code Execution Vulnerability | ||
| CVE-2023-35630 | Hig | 0.58 | 8.8 | 0.06 | Dec 12, 2023 | Internet Connection Sharing (ICS) Remote Code Execution Vulnerability | ||
| CVE-2023-36400 | Hig | 0.58 | 8.8 | 0.04 | Nov 14, 2023 | Windows HMAC Key Derivation Elevation of Privilege Vulnerability | ||
| CVE-2020-1585 | Hig | 0.58 | 8.8 | 0.05 | Aug 17, 2020 | A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or… | ||
| CVE-2019-0888 | Hig | 0.58 | 8.8 | 0.11 | Jun 12, 2019 | A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with the victim user’s privileges. An attacker could craft a website that… | ||
| CVE-2019-0722 | Hig | 0.58 | 8.8 | 0.05 | Jun 12, 2019 | A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating… | ||
| CVE-2026-25188 | Hig | 0.57 | 8.8 | 0.01 | Mar 10, 2026 | Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network. | ||
| CVE-2026-25177 | Hig | 0.57 | 8.8 | 0.01 | Mar 10, 2026 | Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-23669 | Hig | 0.57 | 8.8 | 0.01 | Mar 10, 2026 | Use after free in RPC Runtime allows an authorized attacker to execute code over a network. | ||
| CVE-2026-21255 | Hig | 0.57 | 8.8 | 0.00 | Feb 10, 2026 | Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2026-20868 | Hig | 0.57 | 8.8 | 0.01 | Jan 13, 2026 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-64678 | Hig | 0.57 | 8.8 | 0.01 | Dec 9, 2025 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-62549 | Hig | 0.57 | 8.8 | 0.01 | Dec 9, 2025 | Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-62456 | Hig | 0.57 | 8.8 | 0.01 | Dec 9, 2025 | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network. | ||
| CVE-2025-59295 | Hig | 0.57 | 8.8 | 0.02 | Oct 14, 2025 | Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-58718 | Hig | 0.57 | 8.8 | 0.01 | Oct 14, 2025 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-58716 | Hig | 0.57 | 8.8 | 0.00 | Oct 14, 2025 | Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-58715 | Hig | 0.57 | 8.8 | 0.00 | Oct 14, 2025 | Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. |
- risk 0.58cvss 8.8epss 0.16
Windows Imaging Component Remote Code Execution Vulnerability
- risk 0.58cvss 8.8epss 0.05
Windows Wi-Fi Driver Remote Code Execution Vulnerability
- risk 0.58cvss 8.8epss 0.07
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
- risk 0.58cvss 8.8epss 0.06
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
- risk 0.58cvss 8.8epss 0.04
Windows HMAC Key Derivation Elevation of Privilege Vulnerability
- risk 0.58cvss 8.8epss 0.05
A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or…
- risk 0.58cvss 8.8epss 0.11
A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with the victim user’s privileges. An attacker could craft a website that…
- risk 0.58cvss 8.8epss 0.05
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating…
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network.
- risk 0.57cvss 8.8epss 0.01
Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Use after free in RPC Runtime allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.00
Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.02
Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.00
Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
- risk 0.57cvss 8.8epss 0.00
Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
Page 5 of 73