Windows 10 version 1607
by Microsoft
CVEs (1,459)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-26183 | Med | 0.42 | 6.5 | 0.02 | Apr 9, 2024 | Windows Kerberos Denial of Service Vulnerability | ||
| CVE-2024-21356 | Med | 0.42 | 6.5 | 0.02 | Feb 13, 2024 | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | ||
| CVE-2024-21339 | Med | 0.42 | 6.4 | 0.01 | Feb 13, 2024 | Windows USB Generic Parent Driver Remote Code Execution Vulnerability | ||
| CVE-2024-20684 | Med | 0.42 | 6.5 | 0.01 | Feb 13, 2024 | Windows Hyper-V Denial of Service Vulnerability | ||
| CVE-2024-21314 | Med | 0.42 | 6.5 | 0.02 | Jan 9, 2024 | Microsoft Message Queuing Information Disclosure Vulnerability | ||
| CVE-2024-20690 | Med | 0.42 | 6.5 | 0.01 | Jan 9, 2024 | Windows Nearby Sharing Spoofing Vulnerability | ||
| CVE-2024-20680 | Med | 0.42 | 6.5 | 0.02 | Jan 9, 2024 | Windows Message Queuing Client (MSMQC) Information Disclosure | ||
| CVE-2024-20664 | Med | 0.42 | 6.5 | 0.02 | Jan 9, 2024 | Microsoft Message Queuing Information Disclosure Vulnerability | ||
| CVE-2024-20663 | Med | 0.42 | 6.5 | 0.02 | Jan 9, 2024 | Windows Message Queuing Client (MSMQC) Information Disclosure | ||
| CVE-2024-20660 | Med | 0.42 | 6.5 | 0.02 | Jan 9, 2024 | Microsoft Message Queuing Information Disclosure Vulnerability | ||
| CVE-2023-35642 | Med | 0.42 | 6.5 | 0.01 | Dec 12, 2023 | Internet Connection Sharing (ICS) Denial of Service Vulnerability | ||
| CVE-2023-36398 | Med | 0.42 | 6.5 | 0.01 | Nov 14, 2023 | Windows NTFS Information Disclosure Vulnerability | ||
| CVE-2019-1043 | Med | 0.42 | 6.4 | 0.03 | Jun 12, 2019 | A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the… | ||
| CVE-2025-60723 | Med | 0.41 | 6.3 | 0.01 | Nov 11, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to deny service over a network. | ||
| CVE-2025-48813 | Med | 0.41 | 6.3 | 0.00 | Oct 14, 2025 | Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally. | ||
| CVE-2024-28898 | Med | 0.41 | 6.3 | 0.01 | Apr 9, 2024 | Secure Boot Security Feature Bypass Vulnerability | ||
| CVE-2019-1053 | Med | 0.41 | 6.3 | 0.01 | Jun 12, 2019 | An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the vulnerability could elevate privileges by escaping a sandbox. To exploit this vulnerability, an attacker would require… | ||
| CVE-2019-0986 | Med | 0.41 | 6.3 | 0.02 | Jun 12, 2019 | An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. To exploit this vulnerability, an attacker… | ||
| CVE-2026-25169 | Med | 0.40 | 6.2 | 0.00 | Mar 10, 2026 | Divide by zero in Microsoft Graphics Component allows an unauthorized attacker to deny service locally. | ||
| CVE-2026-25168 | Med | 0.40 | 6.2 | 0.00 | Mar 10, 2026 | Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally. |
- risk 0.42cvss 6.5epss 0.02
Windows Kerberos Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.02
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
- risk 0.42cvss 6.4epss 0.01
Windows USB Generic Parent Driver Remote Code Execution Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows Hyper-V Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.02
Microsoft Message Queuing Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows Nearby Sharing Spoofing Vulnerability
- risk 0.42cvss 6.5epss 0.02
Windows Message Queuing Client (MSMQC) Information Disclosure
- risk 0.42cvss 6.5epss 0.02
Microsoft Message Queuing Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.02
Windows Message Queuing Client (MSMQC) Information Disclosure
- risk 0.42cvss 6.5epss 0.02
Microsoft Message Queuing Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
Internet Connection Sharing (ICS) Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows NTFS Information Disclosure Vulnerability
- risk 0.42cvss 6.4epss 0.03
A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the…
- risk 0.41cvss 6.3epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to deny service over a network.
- risk 0.41cvss 6.3epss 0.00
Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.
- risk 0.41cvss 6.3epss 0.01
Secure Boot Security Feature Bypass Vulnerability
- risk 0.41cvss 6.3epss 0.01
An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the vulnerability could elevate privileges by escaping a sandbox. To exploit this vulnerability, an attacker would require…
- risk 0.41cvss 6.3epss 0.02
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. To exploit this vulnerability, an attacker…
- risk 0.40cvss 6.2epss 0.00
Divide by zero in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.
- risk 0.40cvss 6.2epss 0.00
Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.
Page 62 of 73