Windows 10 1607
by Microsoft
CVEs (3,986)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-28312 | Low | 0.22 | 3.3 | 0.07 | Apr 13, 2021 | Windows NTFS Denial of Service Vulnerability | ||
| CVE-2020-17097 | Low | 0.22 | 3.3 | 0.01 | Dec 10, 2020 | Windows Digital Media Receiver Elevation of Privilege Vulnerability | ||
| CVE-2025-21337 | Low | 0.21 | 3.3 | 0.01 | Feb 11, 2025 | Windows NTFS Elevation of Privilege Vulnerability | ||
| CVE-2023-21759 | Low | 0.21 | 3.3 | 0.01 | Jan 10, 2023 | Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability | ||
| CVE-2022-38022 | Low | 0.21 | 3.3 | 0.01 | Oct 11, 2022 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2018-8482 | Low | 0.21 | 3.1 | 0.05 | Oct 10, 2018 | An information disclosure vulnerability exists when Windows Media Player improperly discloses file information, aka "Windows Media Player Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server… | ||
| CVE-2025-59280 | Low | 0.20 | 3.1 | 0.00 | Oct 14, 2025 | Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network. | ||
| CVE-2025-21312 | Low | 0.16 | 2.4 | 0.01 | Jan 14, 2025 | Windows Smart Card Reader Information Disclosure Vulnerability | ||
| CVE-2025-59294 | Low | 0.14 | 2.1 | 0.01 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack. | ||
| CVE-2026-56155 | Hig | 0.12 | 7.8 | 0.02 | KEV | Jul 14, 2026 | Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally. | |
| CVE-2015-6103 | 0.06 | — | 0.35 | Nov 11, 2015 | The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via… | |||
| CVE-2015-6102 | 0.03 | — | 0.04 | Nov 11, 2015 | The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to bypass the KASLR protection mechanism, and… | |||
| CVE-2015-2524 | 0.03 | — | 0.03 | Sep 9, 2015 | Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows Task Management Elevation of Privilege… | |||
| CVE-2015-2508 | 0.03 | — | 0.04 | Sep 9, 2015 | The Adobe Type Manager Library in Microsoft Windows 10 allows local users to gain privileges via a crafted application, aka "Font Driver Elevation of Privilege Vulnerability." | |||
| CVE-2015-2435 | 0.02 | — | 0.22 | Aug 15, 2015 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1,… | |||
| CVE-2026-50518 | Cri | 0.01 | 9.8 | 0.11 | Jul 14, 2026 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-58598 | Hig | 0.00 | 7.0 | 0.00 | Jul 16, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-58638 | Med | 0.00 | 6.0 | 0.00 | Jul 14, 2026 | Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2026-58637 | Hig | 0.00 | 7.0 | 0.00 | Jul 14, 2026 | Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-58632 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
- risk 0.22cvss 3.3epss 0.07
Windows NTFS Denial of Service Vulnerability
- risk 0.22cvss 3.3epss 0.01
Windows Digital Media Receiver Elevation of Privilege Vulnerability
- risk 0.21cvss 3.3epss 0.01
Windows NTFS Elevation of Privilege Vulnerability
- risk 0.21cvss 3.3epss 0.01
Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability
- risk 0.21cvss 3.3epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.21cvss 3.1epss 0.05
An information disclosure vulnerability exists when Windows Media Player improperly discloses file information, aka "Windows Media Player Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server…
- risk 0.20cvss 3.1epss 0.00
Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.
- risk 0.16cvss 2.4epss 0.01
Windows Smart Card Reader Information Disclosure Vulnerability
- risk 0.14cvss 2.1epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack.
- risk 0.12cvss 7.8epss 0.02
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
- CVE-2015-6103Nov 11, 2015risk 0.06cvss —epss 0.35
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via…
- CVE-2015-6102Nov 11, 2015risk 0.03cvss —epss 0.04
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to bypass the KASLR protection mechanism, and…
- CVE-2015-2524Sep 9, 2015risk 0.03cvss —epss 0.03
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows Task Management Elevation of Privilege…
- CVE-2015-2508Sep 9, 2015risk 0.03cvss —epss 0.04
The Adobe Type Manager Library in Microsoft Windows 10 allows local users to gain privileges via a crafted application, aka "Font Driver Elevation of Privilege Vulnerability."
- CVE-2015-2435Aug 15, 2015risk 0.02cvss —epss 0.22
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1,…
- risk 0.01cvss 9.8epss 0.11
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 6.0epss 0.00
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
- risk 0.00cvss 7.0epss 0.00
Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Page 183 of 200