Windows 10 1909
by Microsoft
CVEs (703)
| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-1478 | 0.01 | — | 0.15 | Aug 17, 2020 | A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Foundation handles objects in memory. | ||
| CVE-2020-1339 | 0.01 | — | 0.14 | Aug 17, 2020 | A remote code execution vulnerability exists when Windows Media Audio Codec improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Audio Codec handles objects. | ||
| CVE-2021-43248 | 0.00 | — | 0.00 | Dec 15, 2021 | Windows Digital Media Receiver Elevation of Privilege Vulnerability | ||
| CVE-2021-43247 | 0.00 | — | 0.01 | Dec 15, 2021 | Windows TCP/IP Driver Elevation of Privilege Vulnerability | ||
| CVE-2021-43246 | 0.00 | — | 0.00 | Dec 15, 2021 | Windows Hyper-V Denial of Service Vulnerability | ||
| CVE-2021-43244 | 0.00 | — | 0.00 | Dec 15, 2021 | Windows Kernel Information Disclosure Vulnerability | ||
| CVE-2021-43240 | 0.00 | — | 0.01 | Dec 15, 2021 | NTFS Set Short Name Elevation of Privilege Vulnerability | ||
| CVE-2021-43238 | 0.00 | — | 0.00 | Dec 15, 2021 | Windows Remote Access Elevation of Privilege Vulnerability | ||
| CVE-2021-43237 | 0.00 | — | 0.01 | Dec 15, 2021 | Windows Setup Elevation of Privilege Vulnerability | ||
| CVE-2021-43235 | 0.00 | — | 0.00 | Dec 15, 2021 | Storage Spaces Controller Information Disclosure Vulnerability | ||
| CVE-2021-43234 | 0.00 | — | 0.01 | Dec 15, 2021 | Windows Fax Service Remote Code Execution Vulnerability | ||
| CVE-2021-43233 | 0.00 | — | 0.03 | Dec 15, 2021 | Remote Desktop Client Remote Code Execution Vulnerability | ||
| CVE-2021-43231 | 0.00 | — | 0.01 | Dec 15, 2021 | Windows NTFS Elevation of Privilege Vulnerability | ||
| CVE-2021-43232 | 0.00 | — | 0.04 | Dec 15, 2021 | Windows Event Tracing Remote Code Execution Vulnerability | ||
| CVE-2021-43230 | 0.00 | — | 0.01 | Dec 15, 2021 | Windows NTFS Elevation of Privilege Vulnerability | ||
| CVE-2021-43227 | 0.00 | — | 0.01 | Dec 15, 2021 | Storage Spaces Controller Information Disclosure Vulnerability | ||
| CVE-2021-43223 | 0.00 | — | 0.00 | Dec 15, 2021 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | ||
| CVE-2021-43219 | 0.00 | — | 0.02 | Dec 15, 2021 | DirectX Graphics Kernel File Denial of Service Vulnerability | ||
| CVE-2021-43215 | 0.00 | — | 0.05 | Dec 15, 2021 | iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution | ||
| CVE-2021-43207 | 0.00 | — | 0.00 | Dec 15, 2021 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
- CVE-2020-1478Aug 17, 2020risk 0.01cvss —epss 0.15
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Foundation handles objects in memory.
- CVE-2020-1339Aug 17, 2020risk 0.01cvss —epss 0.14
A remote code execution vulnerability exists when Windows Media Audio Codec improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Audio Codec handles objects.
- CVE-2021-43248Dec 15, 2021risk 0.00cvss —epss 0.00
Windows Digital Media Receiver Elevation of Privilege Vulnerability
- CVE-2021-43247Dec 15, 2021risk 0.00cvss —epss 0.01
Windows TCP/IP Driver Elevation of Privilege Vulnerability
- CVE-2021-43246Dec 15, 2021risk 0.00cvss —epss 0.00
Windows Hyper-V Denial of Service Vulnerability
- CVE-2021-43244Dec 15, 2021risk 0.00cvss —epss 0.00
Windows Kernel Information Disclosure Vulnerability
- CVE-2021-43240Dec 15, 2021risk 0.00cvss —epss 0.01
NTFS Set Short Name Elevation of Privilege Vulnerability
- CVE-2021-43238Dec 15, 2021risk 0.00cvss —epss 0.00
Windows Remote Access Elevation of Privilege Vulnerability
- CVE-2021-43237Dec 15, 2021risk 0.00cvss —epss 0.01
Windows Setup Elevation of Privilege Vulnerability
- CVE-2021-43235Dec 15, 2021risk 0.00cvss —epss 0.00
Storage Spaces Controller Information Disclosure Vulnerability
- CVE-2021-43234Dec 15, 2021risk 0.00cvss —epss 0.01
Windows Fax Service Remote Code Execution Vulnerability
- CVE-2021-43233Dec 15, 2021risk 0.00cvss —epss 0.03
Remote Desktop Client Remote Code Execution Vulnerability
- CVE-2021-43231Dec 15, 2021risk 0.00cvss —epss 0.01
Windows NTFS Elevation of Privilege Vulnerability
- CVE-2021-43232Dec 15, 2021risk 0.00cvss —epss 0.04
Windows Event Tracing Remote Code Execution Vulnerability
- CVE-2021-43230Dec 15, 2021risk 0.00cvss —epss 0.01
Windows NTFS Elevation of Privilege Vulnerability
- CVE-2021-43227Dec 15, 2021risk 0.00cvss —epss 0.01
Storage Spaces Controller Information Disclosure Vulnerability
- CVE-2021-43223Dec 15, 2021risk 0.00cvss —epss 0.00
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
- CVE-2021-43219Dec 15, 2021risk 0.00cvss —epss 0.02
DirectX Graphics Kernel File Denial of Service Vulnerability
- CVE-2021-43215Dec 15, 2021risk 0.00cvss —epss 0.05
iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution
- CVE-2021-43207Dec 15, 2021risk 0.00cvss —epss 0.00
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Page 11 of 36