Windows 10 1607
by Microsoft
CVEs (3,986)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-0683 | Hig | 0.66 | 7.8 | 0.08 | KEV | Feb 11, 2020 | An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686. | |
| CVE-2019-0863 | Hig | 0.66 | 7.8 | 0.05 | KEV | May 16, 2019 | An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. | |
| CVE-2025-47981 | Cri | 0.65 | 9.8 | 0.33 | Jul 8, 2025 | Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-30397 | Hig | 0.65 | 7.5 | 0.27 | KEV | May 13, 2025 | Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network. | |
| CVE-2023-36397 | Cri | 0.65 | 9.8 | 0.18 | Nov 14, 2023 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | ||
| CVE-2023-44487 | Hig | 0.65 | 7.5 | 1.00 | KEV | Oct 10, 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| CVE-2023-36802 | Hig | 0.65 | 7.8 | 0.28 | KEV | Sep 12, 2023 | Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability | |
| CVE-2023-21692 | Cri | 0.65 | 9.8 | 0.21 | Feb 14, 2023 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | ||
| CVE-2022-26925 | Hig | 0.65 | 8.1 | 0.11 | KEV | May 10, 2022 | Windows LSA Spoofing Vulnerability | |
| CVE-2021-26432 | Cri | 0.65 | 9.8 | 0.11 | Aug 12, 2021 | Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability | ||
| CVE-2021-33742 | Hig | 0.65 | 7.5 | 0.59 | KEV | Jun 8, 2021 | Windows MSHTML Platform Remote Code Execution Vulnerability | |
| CVE-2021-24094 | Cri | 0.65 | 9.8 | 0.22 | Feb 25, 2021 | Windows TCP/IP Remote Code Execution Vulnerability | ||
| CVE-2020-1467 | Cri | 0.65 | 10.0 | 0.04 | Aug 17, 2020 | An elevation of privilege vulnerability exists when Windows improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. To exploit this vulnerability, an attacker would first have to log… | ||
| CVE-2020-1054 | Hig | 0.65 | 7.0 | 0.54 | KEV | May 21, 2020 | An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;… | |
| CVE-2019-1182 | Cri | 0.65 | 9.8 | 0.17 | Aug 14, 2019 | A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and… | ||
| CVE-2026-65791 | Cri | 0.64 | 9.8 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62893 | Cri | 0.64 | 9.8 | 0.03 | Aug 11, 2026 | Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62878 | Cri | 0.64 | 9.8 | 0.01 | Aug 11, 2026 | Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-47291 | Cri | 0.64 | 9.8 | 0.23 | Jun 9, 2026 | Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-44815 | Cri | 0.64 | 9.8 | 0.01 | Jun 9, 2026 | Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network. |
- risk 0.66cvss 7.8epss 0.08
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686.
- risk 0.66cvss 7.8epss 0.05
An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.
- risk 0.65cvss 9.8epss 0.33
Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.
- risk 0.65cvss 7.5epss 0.27
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
- risk 0.65cvss 9.8epss 0.18
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- risk 0.65cvss 7.5epss 1.00
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
- risk 0.65cvss 7.8epss 0.28
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
- risk 0.65cvss 9.8epss 0.21
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
- risk 0.65cvss 8.1epss 0.11
Windows LSA Spoofing Vulnerability
- risk 0.65cvss 9.8epss 0.11
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
- risk 0.65cvss 7.5epss 0.59
Windows MSHTML Platform Remote Code Execution Vulnerability
- risk 0.65cvss 9.8epss 0.22
Windows TCP/IP Remote Code Execution Vulnerability
- risk 0.65cvss 10.0epss 0.04
An elevation of privilege vulnerability exists when Windows improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. To exploit this vulnerability, an attacker would first have to log…
- risk 0.65cvss 7.0epss 0.54
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;…
- risk 0.65cvss 9.8epss 0.17
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and…
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.03
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.23
Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.
Page 6 of 200