windows_10_1909 vulnerabilities
CVEs whose affected-version data names the windows_10_1909 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
18 CVEsRSS
CVE-2022-21882High· 7.0CISA KEV0dayPoCWin32k Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
CVE-2021-43226High· 7.8CISA KEVPoCWindows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-41379Medium· 5.5CISA KEV0dayWindows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
CVE-2021-40444High· 8.8CISA KEV0dayPoCMicrosoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows
Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft …
CVE-2021-36955High· 7.8CISA KEVPoCWindows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-36948High· 7.8CISA KEV0dayWindows Update Medic Service Elevation of Privilege Vulnerability
Windows Update Medic Service Elevation of Privilege Vulnerability
CVE-2021-34486High· 7.8CISA KEVPoCWindows Event Tracing Elevation of Privilege Vulnerability
Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-34484High· 7.8CISA KEVWindows User Profile Service Elevation of Privilege Vulnerability
Windows User Profile Service Elevation of Privilege Vulnerability
CVE-2021-36934High· 7.8CISA KEVPoCAn elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database
An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnera…
CVE-2021-34448Medium· 6.8CISA KEV0dayScripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
CVE-2021-33771High· 7.8CISA KEV0dayWindows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
CVE-2021-31979High· 7.8CISA KEV0dayWindows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
CVE-2021-1675High· 7.8CISA KEVPoCWindows Print Spooler Remote Code Execution Vulnerability
Windows Print Spooler Remote Code Execution Vulnerability
CVE-2021-1732High· 7.8CISA KEV0dayPoCWindows Win32k Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
CVE-2020-1054High· 7.0CISA KEVPoCAn elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. …
CVE-2020-0796Critical· 10.0CISA KEVPoCA remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.
CVE-2020-0787High· 7.8CISA KEVPoCAn elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
CVE-2020-0638High· 7.8CISA KEVAn elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager …
An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager …