Windows 10 1607
by Microsoft
CVEs (3,986)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-21847 | Med | 0.42 | 6.5 | 0.01 | Jan 11, 2022 | Windows Hyper-V Denial of Service Vulnerability | ||
| CVE-2021-43244 | Med | 0.42 | 6.5 | 0.01 | Dec 15, 2021 | Windows Kernel Information Disclosure Vulnerability | ||
| CVE-2021-41332 | Med | 0.42 | 6.5 | 0.03 | Oct 13, 2021 | Windows Print Spooler Information Disclosure Vulnerability | ||
| CVE-2021-40460 | Med | 0.42 | 6.5 | 0.02 | Oct 13, 2021 | Windows Remote Procedure Call Runtime Security Feature Bypass Vulnerability | ||
| CVE-2021-38629 | Med | 0.42 | 6.5 | 0.03 | Sep 15, 2021 | Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability | ||
| CVE-2021-38624 | Med | 0.42 | 6.5 | 0.02 | Sep 15, 2021 | Windows Key Storage Provider Security Feature Bypass Vulnerability | ||
| CVE-2021-34507 | Med | 0.42 | 6.5 | 0.03 | Jul 14, 2021 | Windows Remote Assistance Information Disclosure Vulnerability | ||
| CVE-2021-33783 | Med | 0.42 | 6.5 | 0.03 | Jul 14, 2021 | Windows SMB Information Disclosure Vulnerability | ||
| CVE-2021-31959 | Med | 0.42 | 6.4 | 0.09 | Jun 8, 2021 | Scripting Engine Memory Corruption Vulnerability | ||
| CVE-2021-31205 | Med | 0.42 | 6.5 | 0.03 | May 11, 2021 | Windows SMB Client Security Feature Bypass Vulnerability | ||
| CVE-2021-28328 | Med | 0.42 | 6.5 | 0.02 | Apr 13, 2021 | Windows DNS Information Disclosure Vulnerability | ||
| CVE-2021-28311 | Med | 0.42 | 6.5 | 0.03 | Apr 13, 2021 | Windows Application Compatibility Cache Denial of Service Vulnerability | ||
| CVE-2021-24080 | Med | 0.42 | 6.5 | 0.03 | Feb 25, 2021 | Windows Trust Verification API Denial of Service Vulnerability | ||
| CVE-2020-17040 | Med | 0.42 | 6.5 | 0.03 | Nov 11, 2020 | Windows Hyper-V Security Feature Bypass Vulnerability | ||
| CVE-2020-0904 | Med | 0.42 | 6.5 | 0.01 | Sep 11, 2020 | A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest… | ||
| CVE-2019-1198 | Med | 0.42 | 6.5 | 0.02 | Aug 14, 2019 | An elevation of privilege exists in SyncController.dll. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that could exploit the… | ||
| CVE-2019-1043 | Med | 0.42 | 6.4 | 0.03 | Jun 12, 2019 | A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the… | ||
| CVE-2025-60723 | Med | 0.41 | 6.3 | 0.01 | Nov 11, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to deny service over a network. | ||
| CVE-2025-48813 | Med | 0.41 | 6.3 | 0.00 | Oct 14, 2025 | Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally. | ||
| CVE-2024-28898 | Med | 0.41 | 6.3 | 0.01 | Apr 9, 2024 | Secure Boot Security Feature Bypass Vulnerability |
- risk 0.42cvss 6.5epss 0.01
Windows Hyper-V Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows Kernel Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.03
Windows Print Spooler Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.02
Windows Remote Procedure Call Runtime Security Feature Bypass Vulnerability
- risk 0.42cvss 6.5epss 0.03
Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.02
Windows Key Storage Provider Security Feature Bypass Vulnerability
- risk 0.42cvss 6.5epss 0.03
Windows Remote Assistance Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.03
Windows SMB Information Disclosure Vulnerability
- risk 0.42cvss 6.4epss 0.09
Scripting Engine Memory Corruption Vulnerability
- risk 0.42cvss 6.5epss 0.03
Windows SMB Client Security Feature Bypass Vulnerability
- risk 0.42cvss 6.5epss 0.02
Windows DNS Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.03
Windows Application Compatibility Cache Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.03
Windows Trust Verification API Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.03
Windows Hyper-V Security Feature Bypass Vulnerability
- risk 0.42cvss 6.5epss 0.01
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest…
- risk 0.42cvss 6.5epss 0.02
An elevation of privilege exists in SyncController.dll. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that could exploit the…
- risk 0.42cvss 6.4epss 0.03
A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the…
- risk 0.41cvss 6.3epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to deny service over a network.
- risk 0.41cvss 6.3epss 0.00
Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.
- risk 0.41cvss 6.3epss 0.01
Secure Boot Security Feature Bypass Vulnerability
Page 154 of 200