Windows 10 1607
by Microsoft
CVEs (3,986)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-42914 | Med | 0.34 | 5.3 | 0.01 | Jun 9, 2026 | Windows Kerberos Denial of Service Vulnerability | ||
| CVE-2025-55229 | Med | 0.34 | 5.3 | 0.00 | Aug 21, 2025 | Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2021-41346 | Med | 0.34 | 5.3 | 0.01 | Oct 13, 2021 | Console Window Host Security Feature Bypass Vulnerability | ||
| CVE-2026-61368 | Med | 0.33 | 5.0 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59198 | Med | 0.33 | 5.0 | 0.00 | Oct 14, 2025 | Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally. | ||
| CVE-2025-55679 | Med | 0.33 | 5.1 | 0.00 | Oct 14, 2025 | Improper input validation in Windows Kernel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2025-26644 | Med | 0.33 | 5.1 | 0.01 | Apr 8, 2025 | Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally. | ||
| CVE-2024-43520 | Med | 0.33 | 5.0 | 0.01 | Oct 8, 2024 | Windows Kernel Denial of Service Vulnerability | ||
| CVE-2024-26220 | Med | 0.33 | 5.0 | 0.01 | Apr 9, 2024 | Windows Mobile Hotspot Information Disclosure Vulnerability | ||
| CVE-2021-1684 | Med | 0.33 | 5.0 | 0.02 | Jan 12, 2021 | Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software update that… | ||
| CVE-2021-1683 | Med | 0.33 | 5.0 | 0.02 | Jan 12, 2021 | Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software update that… | ||
| CVE-2021-1645 | Med | 0.33 | 5.0 | 0.07 | Jan 12, 2021 | Windows Docker Information Disclosure Vulnerability | ||
| CVE-2020-0837 | Med | 0.33 | 5.0 | 0.01 | Sep 11, 2020 | An elevation of privilege vulnerability exists when Active Directory Federation Services (ADFS) improperly handles multi-factor authentication requests. An attacker who successfully exploited this vulnerability could bypass some, but not all, of the authentication… | ||
| CVE-2016-3256 | Med | 0.33 | 5.0 | 0.03 | Jul 13, 2016 | Microsoft Windows 10 Gold and 1511 allows local users to bypass the Secure Kernel Mode protection mechanism and obtain sensitive information via a crafted application, aka "Windows Secure Kernel Mode Information Disclosure Vulnerability." | ||
| CVE-2026-33829 | Med | 0.31 | 4.3 | 0.03 | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-58719 | Med | 0.31 | 4.7 | 0.00 | Oct 14, 2025 | Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-54101 | Med | 0.31 | 4.8 | 0.03 | Sep 9, 2025 | Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network. | ||
| CVE-2024-30071 | Med | 0.31 | 4.7 | 0.01 | Jul 9, 2024 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | ||
| CVE-2024-30069 | Med | 0.31 | 4.7 | 0.01 | Jun 11, 2024 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | ||
| CVE-2024-20691 | Med | 0.31 | 4.7 | 0.01 | Jan 9, 2024 | Windows Themes Information Disclosure Vulnerability |
- risk 0.34cvss 5.3epss 0.01
Windows Kerberos Denial of Service Vulnerability
- risk 0.34cvss 5.3epss 0.00
Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoofing over a network.
- risk 0.34cvss 5.3epss 0.01
Console Window Host Security Feature Bypass Vulnerability
- risk 0.33cvss 5.0epss 0.00
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.
- risk 0.33cvss 5.0epss 0.00
Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
- risk 0.33cvss 5.1epss 0.00
Improper input validation in Windows Kernel allows an unauthorized attacker to disclose information locally.
- risk 0.33cvss 5.1epss 0.01
Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.
- risk 0.33cvss 5.0epss 0.01
Windows Kernel Denial of Service Vulnerability
- risk 0.33cvss 5.0epss 0.01
Windows Mobile Hotspot Information Disclosure Vulnerability
- risk 0.33cvss 5.0epss 0.02
Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software update that…
- risk 0.33cvss 5.0epss 0.02
Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software update that…
- risk 0.33cvss 5.0epss 0.07
Windows Docker Information Disclosure Vulnerability
- risk 0.33cvss 5.0epss 0.01
An elevation of privilege vulnerability exists when Active Directory Federation Services (ADFS) improperly handles multi-factor authentication requests. An attacker who successfully exploited this vulnerability could bypass some, but not all, of the authentication…
- risk 0.33cvss 5.0epss 0.03
Microsoft Windows 10 Gold and 1511 allows local users to bypass the Secure Kernel Mode protection mechanism and obtain sensitive information via a crafted application, aka "Windows Secure Kernel Mode Information Disclosure Vulnerability."
- risk 0.31cvss 4.3epss 0.03
Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.
- risk 0.31cvss 4.7epss 0.00
Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
- risk 0.31cvss 4.8epss 0.03
Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network.
- risk 0.31cvss 4.7epss 0.01
Windows Remote Access Connection Manager Information Disclosure Vulnerability
- risk 0.31cvss 4.7epss 0.01
Windows Remote Access Connection Manager Information Disclosure Vulnerability
- risk 0.31cvss 4.7epss 0.01
Windows Themes Information Disclosure Vulnerability
Page 178 of 200