VulnSea

windows_10_version_22h2 vulnerabilities

CVEs whose affected-version data names the windows_10_version_22h2 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

615 CVEsRSS

CVE-2026-56644High· 7.8
2mo ago

DirectX Graphics Kernel Elevation of Privilege Vulnerability

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-56643High· 7.8
2mo ago

DirectX Graphics Kernel Elevation of Privilege Vulnerability

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-56194High· 8.8
2mo ago

Windows NFS Server Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.91%via CVEORG
CVE-2026-56189High· 7.8
2mo ago

Microsoft Windows Media Foundation Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.39%via CVEORG
CVE-2026-54124High· 7.8
2mo ago

Windows Terminal Remote Code Execution Vulnerability

Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 21H2EPSS 0.47%via CVEORG
CVE-2026-57095Medium· 6.2
2mo ago

Win32k Elevation of Privilege Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.49%via CVEORG
CVE-2026-57096High· 7.8
2mo ago

Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-57982Medium· 6.5
2mo ago

Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 1.00%via CVEORG
CVE-2026-58546Medium· 6.5
2mo ago

Windows Remote Desktop Client Information Disclosure Vulnerability

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.92%via CVEORG
CVE-2026-58539Medium· 6.5
2mo ago

Windows Remote Desktop Client Information Disclosure Vulnerability

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.92%via CVEORG
CVE-2026-58538High· 7.8
2mo ago

Windows Bluetooth Service Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.33%via CVEORG
CVE-2026-58535Medium· 6.5
2mo ago

Windows Remote Desktop Client Information Disclosure Vulnerability

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.92%via CVEORG
CVE-2026-58534High· 8.8
2mo ago

Windows Input Method Editor (IME) Elevation of Privilege Vulnerability

Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-58533Medium· 6.5
2mo ago

Windows Remote Desktop Client Information Disclosure Vulnerability

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.92%via CVEORG
CVE-2026-58532High· 7.8
2mo ago

Windows Kernel Elevation of Privilege Vulnerability

Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-58531High· 7.5
2mo ago

Windows SMB Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.51%via CVEORG
CVE-2026-58530High· 7.8
2mo ago

Windows Resilient File System (ReFS) Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.36%via CVEORG
CVE-2026-58528Medium· 6.8
2mo ago

Windows USB Audio Class Driver Information Disclosure Vulnerability

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

▾ SunlitMicrosoft · Windows 10 Version 1809EPSS 0.52%via CVEORG
CVE-2026-58594High· 8.8
2mo ago

Remote Desktop Client Remote Code Execution Vulnerability

Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.82%via CVEORG
CVE-2026-58547Medium· 5.5
2mo ago

Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability

Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.

▾ SunlitMicrosoft · Windows 10 Version 1809EPSS 0.41%via CVEORG
CVE-2026-58545Medium· 5.5
2mo ago

Windows Kernel Security Feature Bypass Vulnerability

Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.35%via CVEORG
CVE-2026-58540High· 7.8
2mo ago

Windows Installer Elevation of Privilege Vulnerability

Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.30%via CVEORG
CVE-2026-58536High· 7.8
2mo ago

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.33%via CVEORG
CVE-2026-58626High· 8.8
2mo ago

Windows Remote Desktop Services Remote Code Execution Vulnerability

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows 10 Version 21H2EPSS 0.91%via CVEORG
CVE-2026-58619High· 7.0
2mo ago

Windows Sensor Data Service Elevation of Privilege Vulnerability

Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-58613High· 7.8
2mo ago

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.38%via CVEORG
CVE-2026-58541High· 7.8
2mo ago

Microsoft DWM Core Library Elevation of Privilege Vulnerability

Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-58638Medium· 6.0
2mo ago

Windows Boot Loader Security Feature Bypass Vulnerability

Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

▾ SunlitMicrosoft · Windows 10 Version 1809EPSS 0.24%via CVEORG
CVE-2026-58637High· 7.0
2mo ago

Windows Client-Side Caching Elevation of Privilege Vulnerability

Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-58632High· 7.8
2mo ago

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
windows_10_version_22h2 vulnerabilities (CVEs) — page 14 · VulnSea