Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Microsoft Subscribe
Filtered by product Windows 10
Total 4164 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-17000 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2020-11-18 2.1 LOW 5.5 MEDIUM
Remote Desktop Protocol Client Information Disclosure Vulnerability
CVE-2020-17069 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2020-11-16 2.1 LOW 5.5 MEDIUM
Windows NDIS Information Disclosure Vulnerability
CVE-2020-17071 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2020-11-16 2.1 LOW 5.5 MEDIUM
Windows Delivery Optimization Information Disclosure Vulnerability
CVE-2020-16902 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2020-10-27 7.2 HIGH 7.8 HIGH
An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows Installer Elevation of Privilege Vulnerability'.
CVE-2020-16927 1 Microsoft 6 Windows 10, Windows 8.1, Windows Rt 8.1 and 3 more 2020-10-23 7.8 HIGH 7.5 HIGH
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
CVE-2020-16891 1 Microsoft 7 Windows 10, Windows 7, Windows 8.1 and 4 more 2020-10-23 7.2 HIGH 8.8 HIGH
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'.
CVE-2020-16898 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2020-10-23 5.8 MEDIUM 8.8 HIGH
A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets, aka 'Windows TCP/IP Remote Code Execution Vulnerability'.
CVE-2020-16899 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2020-10-22 7.8 HIGH 7.5 HIGH
A denial of service vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets, aka 'Windows TCP/IP Denial of Service Vulnerability'.
CVE-2020-16897 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2020-10-22 2.1 LOW 5.5 MEDIUM
An information disclosure vulnerability exists when NetBIOS over TCP (NBT) Extensions (NetBT) improperly handle objects in memory, aka 'NetBT Information Disclosure Vulnerability'.
CVE-2020-16940 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2020-10-21 4.9 MEDIUM 5.5 MEDIUM
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points, aka 'Windows - User Profile Service Elevation of Privilege Vulnerability'.
CVE-2020-16949 1 Microsoft 11 365 Apps, Office, Outlook and 8 more 2020-10-21 5.0 MEDIUM 7.5 HIGH
A denial of service vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory, aka 'Microsoft Outlook Denial of Service Vulnerability'.
CVE-2020-16910 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2020-10-21 4.3 MEDIUM 5.5 MEDIUM
A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location.To exploit this vulnerability, an attacker could run a specially crafted application to bypass Unified Extensible Firmware Interface (UEFI) variable security in Windows.The security update addresses the vulnerability by correcting security feature behavior to enforce permissions., aka 'Windows Security Feature Bypass Vulnerability'.
CVE-2020-1243 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2020-10-21 4.6 MEDIUM 7.8 HIGH
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system.To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application.The security update addresses the vulnerability by resolving the conditions where Hyper-V would fail to handle these requests., aka 'Windows Hyper-V Denial of Service Vulnerability'.
CVE-2020-16901 1 Microsoft 2 Windows 10, Windows Server 2016 2020-10-20 2.1 LOW 5.5 MEDIUM
An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.To exploit this vulnerability, an authenticated attacker could run a specially crafted application, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-16938.
CVE-2020-16938 1 Microsoft 2 Windows 10, Windows Server 2016 2020-10-20 2.1 LOW 5.5 MEDIUM
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-16901.
CVE-2020-16922 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2020-10-20 2.1 LOW 5.5 MEDIUM
A spoofing vulnerability exists when Windows incorrectly validates file signatures, aka 'Windows Spoofing Vulnerability'.
CVE-2020-16923 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2020-10-20 6.8 MEDIUM 7.8 HIGH
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1167.
CVE-2020-16915 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2020-10-20 6.8 MEDIUM 8.8 HIGH
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'.
CVE-2020-16911 1 Microsoft 7 Windows 10, Windows 7, Windows 8.1 and 4 more 2020-10-20 9.3 HIGH 8.8 HIGH
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
CVE-2019-9510 1 Microsoft 2 Windows 10, Windows Server 2019 2020-10-19 4.6 MEDIUM 7.8 HIGH
A vulnerability in Microsoft Windows 10 1803 and Windows Server 2019 and later systems can allow authenticated RDP-connected clients to gain access to user sessions without needing to interact with the Windows lock screen. Should a network anomaly trigger a temporary RDP disconnect, Automatic Reconnection of the RDP session will be restored to an unlocked state, regardless of how the remote system was left. By interrupting network connectivity of a system, an attacker with access to a system being used as a Windows RDP client can gain access to a connected remote system, regardless of whether or not the remote system was locked. This issue affects Microsoft Windows 10, version 1803 and later, and Microsoft Windows Server 2019, version 2019 and later.