Windows 10 1607
by Microsoft
CVEs (3,986)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-1014 | Hig | 0.46 | 7.0 | 0.01 | Jun 12, 2019 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view,… | ||
| CVE-2019-0984 | Hig | 0.46 | 7.0 | 0.01 | Jun 12, 2019 | An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vulnerability, an… | ||
| CVE-2018-8399 | Hig | 0.46 | 7.0 | 0.01 | Aug 15, 2018 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID is unique from CVE-2018-8404. | ||
| CVE-2018-8170 | Hig | 0.46 | 7.0 | 0.01 | May 9, 2018 | An elevation of privilege vulnerability exists in the way that the Windows kernel image handles objects in memory, aka "Windows Image Elevation of Privilege Vulnerability." This affects Windows 10, Windows 10 Servers. | ||
| CVE-2018-0809 | Hig | 0.46 | 7.0 | 0.01 | Feb 15, 2018 | The Windows kernel in Windows 10, versions 1703 and 1709, and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0742,… | ||
| CVE-2026-47648 | Hig | 0.45 | 7.0 | 0.00 | Jun 9, 2026 | Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-42984 | Hig | 0.45 | 7.0 | 0.00 | Jun 9, 2026 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-34335 | Hig | 0.45 | 7.0 | 0.00 | Jun 9, 2026 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | ||
| CVE-2022-37974 | Med | 0.45 | 6.5 | 0.36 | Oct 11, 2022 | Windows Mixed Reality Developer Tools Information Disclosure Vulnerability | ||
| CVE-2020-1034 | Med | 0.45 | 6.8 | 0.05 | Sep 11, 2020 | An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated… | ||
| CVE-2026-70330 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-70304 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65799 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65798 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65797 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65795 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62883 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62881 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62769 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62702 | Med | 0.44 | 6.8 | 0.01 | Aug 11, 2026 | Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network. |
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view,…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vulnerability, an…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID is unique from CVE-2018-8404.
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability exists in the way that the Windows kernel image handles objects in memory, aka "Windows Image Elevation of Privilege Vulnerability." This affects Windows 10, Windows 10 Servers.
- risk 0.46cvss 7.0epss 0.01
The Windows kernel in Windows 10, versions 1703 and 1709, and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0742,…
- risk 0.45cvss 7.0epss 0.00
Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.
- risk 0.45cvss 7.0epss 0.00
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.45cvss 7.0epss 0.00
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- risk 0.45cvss 6.5epss 0.36
Windows Mixed Reality Developer Tools Information Disclosure Vulnerability
- risk 0.45cvss 6.8epss 0.05
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated…
- risk 0.44cvss 6.7epss 0.00
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.8epss 0.01
Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.
Page 136 of 200