Windows 10 version 1607
by Microsoft
CVEs (1,387)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-20935 | Med | 0.40 | 6.2 | 0.00 | Jan 13, 2026 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-20821 | Med | 0.40 | 6.2 | 0.01 | Jan 13, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally. | ||
| CVE-2025-55338 | Med | 0.40 | 6.1 | 0.03 | Oct 14, 2025 | Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | ||
| CVE-2025-55334 | Med | 0.40 | 6.2 | 0.00 | Oct 14, 2025 | Cleartext storage of sensitive information in Windows Kernel allows an unauthorized attacker to bypass a security feature locally. | ||
| CVE-2025-55333 | Med | 0.40 | 6.1 | 0.01 | Oct 14, 2025 | Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | ||
| CVE-2025-55332 | Med | 0.40 | 6.1 | 0.01 | Oct 14, 2025 | Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | ||
| CVE-2025-55330 | Med | 0.40 | 6.1 | 0.01 | Oct 14, 2025 | Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | ||
| CVE-2025-47980 | Med | 0.40 | 6.2 | 0.01 | Jul 8, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker to disclose information locally. | ||
| CVE-2025-29957 | Med | 0.40 | 6.2 | 0.01 | May 13, 2025 | Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally. | ||
| CVE-2025-21278 | Med | 0.40 | 6.2 | 0.01 | Jan 14, 2025 | Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | ||
| CVE-2025-21202 | Med | 0.40 | 6.1 | 0.01 | Jan 14, 2025 | Windows Recovery Environment Agent Elevation of Privilege Vulnerability | ||
| CVE-2024-38203 | Med | 0.40 | 6.2 | 0.01 | Nov 12, 2024 | Windows Package Library Manager Information Disclosure Vulnerability | ||
| CVE-2024-29064 | Med | 0.40 | 6.2 | 0.01 | Apr 9, 2024 | Windows Hyper-V Denial of Service Vulnerability | ||
| CVE-2024-20665 | Med | 0.40 | 6.1 | 0.01 | Apr 9, 2024 | BitLocker Security Feature Bypass Vulnerability | ||
| CVE-2024-21316 | Med | 0.40 | 6.1 | 0.01 | Jan 9, 2024 | Windows Server Key Distribution Service Security Feature Bypass | ||
| CVE-2025-27735 | Med | 0.39 | 6.0 | 0.00 | Apr 8, 2025 | Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2025-21350 | Med | 0.39 | 5.9 | 0.02 | Feb 11, 2025 | Windows Kerberos Denial of Service Vulnerability | ||
| CVE-2025-21347 | Med | 0.39 | 6.0 | 0.01 | Feb 11, 2025 | Windows Deployment Services Denial of Service Vulnerability | ||
| CVE-2025-48823 | Med | 0.38 | 5.9 | 0.01 | Jul 8, 2025 | Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-29954 | Med | 0.38 | 5.9 | 0.01 | May 13, 2025 | Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. |
- risk 0.40cvss 6.2epss 0.00
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally.
- risk 0.40cvss 6.2epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally.
- risk 0.40cvss 6.1epss 0.03
Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- risk 0.40cvss 6.2epss 0.00
Cleartext storage of sensitive information in Windows Kernel allows an unauthorized attacker to bypass a security feature locally.
- risk 0.40cvss 6.1epss 0.01
Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- risk 0.40cvss 6.1epss 0.01
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- risk 0.40cvss 6.1epss 0.01
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- risk 0.40cvss 6.2epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker to disclose information locally.
- risk 0.40cvss 6.2epss 0.01
Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally.
- risk 0.40cvss 6.2epss 0.01
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
- risk 0.40cvss 6.1epss 0.01
Windows Recovery Environment Agent Elevation of Privilege Vulnerability
- risk 0.40cvss 6.2epss 0.01
Windows Package Library Manager Information Disclosure Vulnerability
- risk 0.40cvss 6.2epss 0.01
Windows Hyper-V Denial of Service Vulnerability
- risk 0.40cvss 6.1epss 0.01
BitLocker Security Feature Bypass Vulnerability
- risk 0.40cvss 6.1epss 0.01
Windows Server Key Distribution Service Security Feature Bypass
- risk 0.39cvss 6.0epss 0.00
Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
- risk 0.39cvss 5.9epss 0.02
Windows Kerberos Denial of Service Vulnerability
- risk 0.39cvss 6.0epss 0.01
Windows Deployment Services Denial of Service Vulnerability
- risk 0.38cvss 5.9epss 0.01
Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a network.
- risk 0.38cvss 5.9epss 0.01
Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
Page 60 of 70