VYPR

Windows 10 1909

by Microsoft

CVEs (4,279)

  • CVE-2021-26414MedJun 8, 2021
    risk 0.35cvss 4.8epss 0.50

    Windows DCOM Server Security Feature Bypass

  • CVE-2020-17090MedNov 11, 2020
    risk 0.35cvss 5.3epss 0.03

    Microsoft Defender for Endpoint Security Feature Bypass Vulnerability

  • CVE-2020-16922MedOct 16, 2020
    risk 0.35cvss 5.3epss 0.01

    A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass security…

  • CVE-2020-1596MedSep 11, 2020
    risk 0.35cvss 5.4epss 0.01

    A information disclosure vulnerability exists when TLS components use weak hash algorithms. An attacker who successfully exploited this vulnerability could obtain information to further compromise a users's encrypted transmission channel. To exploit the vulnerability,…

  • CVE-2020-0805MedSep 11, 2020
    risk 0.35cvss 5.3epss 0.01

    A security feature bypass vulnerability exists when a Windows Projected Filesystem improperly handles file redirections. An attacker who successfully exploited this vulnerability could delete a targeted file they would not have permissions to. To exploit this…

  • CVE-2020-1434MedJul 14, 2020
    risk 0.35cvss 5.3epss 0.01

    An elevation of privilege vulnerability exists in the way that the Windows Sync Host Service handles objects in memory, aka 'Windows Sync Host Service Elevation of Privilege Vulnerability'.

  • CVE-2020-1113MedMay 21, 2020
    risk 0.35cvss 5.3epss 0.06

    A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over RPC. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator. An attacker could…

  • CVE-2019-9510MedJan 15, 2020
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in Microsoft Windows 10 1803 and Windows Server 2019 and later systems can allow authenticated RDP-connected clients to gain access to user sessions without needing to interact with the Windows lock screen. Should a network anomaly trigger a temporary RDP…

  • CVE-2019-1324MedNov 12, 2019
    risk 0.35cvss 5.3epss 0.04

    An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles IPv6 flowlabel filled in packets, aka 'Windows TCP/IP Information Disclosure Vulnerability'.

  • CVE-2019-1273MedSep 11, 2019
    risk 0.35cvss 5.4epss 0.02

    A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize certain error messages, aka 'Active Directory Federation Services XSS Vulnerability'.

  • CVE-2019-1044MedJun 12, 2019
    risk 0.35cvss 5.3epss 0.01

    A security feature bypass vulnerability exists when Windows Secure Kernel Mode fails to properly handle objects in memory. To exploit the vulnerability, a locally-authenticated attacker could attempt to run a specially crafted application on a targeted system. An attacker who…

  • CVE-2019-0948MedJun 12, 2019
    risk 0.35cvss 4.7epss 0.13

    An information disclosure vulnerability exists in the Windows Event Viewer (eventvwr.msc) when it improperly parses XML input containing a reference to an external entity. An attacker who successfully exploited this vulnerability could read arbitrary files via an XML external…

  • CVE-2019-0733MedMay 16, 2019
    risk 0.35cvss 5.3epss 0.01

    A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'.

  • CVE-2018-8547MedNov 14, 2018
    risk 0.35cvss 5.4epss 0.02

    A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Federation Services (AD FS) does not properly sanitize a specially crafted web request to an affected AD FS server, aka "Active Directory Federation Services XSS…

  • CVE-2018-8417MedNov 14, 2018
    risk 0.35cvss 5.3epss 0.02

    A security feature bypass vulnerability exists in Microsoft JScript that could allow an attacker to bypass Device Guard, aka "Microsoft JScript Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers.

  • CVE-2018-8492MedOct 10, 2018
    risk 0.35cvss 5.3epss 0.02

    A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10,…

  • CVE-2018-8434MedSep 13, 2018
    risk 0.35cvss 5.4epss 0.03

    An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Information Disclosure Vulnerability." This affects Windows 7, Windows…

  • CVE-2018-8337MedSep 13, 2018
    risk 0.35cvss 5.3epss 0.01

    A security feature bypass vulnerability exists when Windows Subsystem for Linux improperly handles case sensitivity, aka "Windows Subsystem for Linux Security Feature Bypass Vulnerability." This affects Windows 10, Windows 10 Servers.

  • CVE-2018-8204MedAug 15, 2018
    risk 0.35cvss 5.3epss 0.01

    A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10,…

  • CVE-2018-8200MedAug 15, 2018
    risk 0.35cvss 5.3epss 0.01

    A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10,…

Page 200 of 214