Windows 10 1809
by Microsoft
CVEs (3,332)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-26160 | Hig | 0.51 | 7.8 | 0.00 | Apr 14, 2026 | Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-26159 | Hig | 0.51 | 7.8 | 0.00 | Apr 14, 2026 | Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-26156 | Hig | 0.51 | 7.8 | 0.00 | Apr 14, 2026 | Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-26153 | Hig | 0.51 | 7.8 | 0.00 | Apr 14, 2026 | Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20930 | Hig | 0.51 | 7.8 | 0.00 | Apr 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-26128 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2026 | Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-25187 | Hig | 0.51 | 7.8 | 0.03 | Mar 10, 2026 | Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20864 | Hig | 0.51 | 7.8 | 0.01 | Jan 13, 2026 | Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-30388 | Hig | 0.51 | 7.8 | 0.03 | May 13, 2025 | Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-21338 | Hig | 0.51 | 7.8 | 0.00 | Jan 14, 2025 | GDI+ Remote Code Execution Vulnerability | ||
| CVE-2024-38250 | Hig | 0.51 | 7.8 | 0.01 | Sep 10, 2024 | Windows Graphics Component Elevation of Privilege Vulnerability | ||
| CVE-2024-20698 | Hig | 0.51 | 7.8 | 0.09 | Jan 9, 2024 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2024-20683 | Hig | 0.51 | 7.8 | 0.04 | Jan 9, 2024 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2024-20682 | Hig | 0.51 | 7.8 | 0.01 | Jan 9, 2024 | Windows Cryptographic Services Remote Code Execution Vulnerability | ||
| CVE-2024-20658 | Hig | 0.51 | 7.8 | 0.01 | Jan 9, 2024 | Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability | ||
| CVE-2024-20653 | Hig | 0.51 | 7.8 | 0.04 | Jan 9, 2024 | Microsoft Common Log File System Elevation of Privilege Vulnerability | ||
| CVE-2023-36696 | Hig | 0.51 | 7.8 | 0.01 | Dec 12, 2023 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | ||
| CVE-2023-36011 | Hig | 0.51 | 7.8 | 0.01 | Dec 12, 2023 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2023-36005 | Hig | 0.51 | 7.5 | 0.24 | Dec 12, 2023 | Windows Telephony Server Elevation of Privilege Vulnerability | ||
| CVE-2023-35644 | Hig | 0.51 | 7.8 | 0.06 | Dec 12, 2023 | Windows Sysmain Service Elevation of Privilege Vulnerability |
- risk 0.51cvss 7.8epss 0.00
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.03
Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.03
Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
GDI+ Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Graphics Component Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.09
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.04
Win32k Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Cryptographic Services Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.04
Microsoft Common Log File System Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Win32k Elevation of Privilege Vulnerability
- risk 0.51cvss 7.5epss 0.24
Windows Telephony Server Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.06
Windows Sysmain Service Elevation of Privilege Vulnerability
Page 28 of 167