Windows 10 1909
by Microsoft
CVEs (3,248)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-11779 | Hig | 0.55 | 8.1 | 0.33 | Oct 13, 2017 | The Microsoft Windows Domain Name System (DNS) DNSAPI.dll on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly handle DNS responses,… | ||
| CVE-2016-3376 | Hig | 0.55 | 7.8 | 0.13 | Oct 14, 2016 | The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka… | ||
| CVE-2016-3238 | Hig | 0.55 | 8.1 | 0.35 | Jul 13, 2016 | The Print Spooler service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows man-in-the-middle attackers to execute arbitrary code by providing a… | ||
| CVE-2016-0135 | Hig | 0.55 | 8.4 | 0.02 | Apr 12, 2016 | The Secondary Logon Service in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Secondary Logon Elevation of Privilege Vulnerability." | ||
| CVE-2016-0092 | Hig | 0.55 | 7.8 | 0.58 | Mar 9, 2016 | OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted file, aka "Windows OLE Memory Remote… | ||
| CVE-2015-1769 | Med | 0.55 | 6.6 | 0.04 | KEV | Aug 15, 2015 | Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks, which allows physically proximate attackers to execute arbitrary… | |
| CVE-2025-49730 | Hig | 0.54 | 7.8 | 0.01 | Jul 8, 2025 | Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-49683 | Hig | 0.54 | 7.8 | 0.02 | Jul 8, 2025 | Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-47987 | Hig | 0.54 | 7.8 | 0.02 | Jul 8, 2025 | Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally. | ||
| CVE-2024-49122 | Hig | 0.54 | 8.1 | 0.20 | Dec 12, 2024 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||
| CVE-2024-30038 | Hig | 0.54 | 7.8 | 0.03 | May 14, 2024 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2024-21407 | Hig | 0.54 | 8.1 | 0.16 | Mar 12, 2024 | Windows Hyper-V Remote Code Execution Vulnerability | ||
| CVE-2023-36606 | Hig | 0.54 | 7.5 | 0.67 | Oct 10, 2023 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2023-28293 | Hig | 0.54 | 7.8 | 0.03 | Apr 11, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-28220 | Hig | 0.54 | 8.1 | 0.15 | Apr 11, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2023-28219 | Hig | 0.54 | 8.1 | 0.15 | Apr 11, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2022-44666 | Hig | 0.54 | 7.8 | 0.40 | Dec 13, 2022 | Windows Contacts Remote Code Execution Vulnerability | ||
| CVE-2021-31955 | Med | 0.54 | 5.5 | 0.80 | KEV | Jun 8, 2021 | Windows Kernel Information Disclosure Vulnerability | |
| CVE-2020-17140 | Hig | 0.54 | 8.1 | 0.12 | Dec 10, 2020 | Windows SMB Information Disclosure Vulnerability | ||
| CVE-2019-0943 | Hig | 0.54 | 7.8 | 0.02 | Jun 12, 2019 | An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then… |
- risk 0.55cvss 8.1epss 0.33
The Microsoft Windows Domain Name System (DNS) DNSAPI.dll on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly handle DNS responses,…
- risk 0.55cvss 7.8epss 0.13
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka…
- risk 0.55cvss 8.1epss 0.35
The Print Spooler service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows man-in-the-middle attackers to execute arbitrary code by providing a…
- risk 0.55cvss 8.4epss 0.02
The Secondary Logon Service in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Secondary Logon Elevation of Privilege Vulnerability."
- risk 0.55cvss 7.8epss 0.58
OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted file, aka "Windows OLE Memory Remote…
- risk 0.55cvss 6.6epss 0.04
Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks, which allows physically proximate attackers to execute arbitrary…
- risk 0.54cvss 7.8epss 0.01
Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally.
- risk 0.54cvss 7.8epss 0.02
Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally.
- risk 0.54cvss 7.8epss 0.02
Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally.
- risk 0.54cvss 8.1epss 0.20
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- risk 0.54cvss 7.8epss 0.03
Win32k Elevation of Privilege Vulnerability
- risk 0.54cvss 8.1epss 0.16
Windows Hyper-V Remote Code Execution Vulnerability
- risk 0.54cvss 7.5epss 0.67
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.54cvss 7.8epss 0.03
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.54cvss 8.1epss 0.15
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.54cvss 8.1epss 0.15
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.54cvss 7.8epss 0.40
Windows Contacts Remote Code Execution Vulnerability
- risk 0.54cvss 5.5epss 0.80
Windows Kernel Information Disclosure Vulnerability
- risk 0.54cvss 8.1epss 0.12
Windows SMB Information Disclosure Vulnerability
- risk 0.54cvss 7.8epss 0.02
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then…
Page 30 of 163