Microsoft
Microsoft Windows 10 1909: vulnerabilidades y CVE
Microsoft Windows 10 1909 tiene 47 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 44 figuran en el catálogo de explotación activa de CISA.
CVE47
Últimos 12 meses0
Críticas1
Explotadas activamente44
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-43226 | Alta (7.8) | 3.1% | ⚠ Explotación activa | 15 dic 2021 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2022-21971 | Alta (7.8) | 54% | ⚠ Explotación activa | 9 feb 2022 | Windows Runtime Remote Code Execution Vulnerability |
| CVE-2022-26923 | Alta (8.8) | 84% | ⚠ Explotación activa | 10 may 2022 | Active Directory Domain Services Elevation of Privilege Vulnerability |
| CVE-2022-26925 | Media (5.9) | 10% | ⚠ Explotación activa | 10 may 2022 | Windows LSA Spoofing Vulnerability |
| CVE-2020-1027 | Alta (7.8) | 4.5% | ⚠ Explotación activa | 15 abr 2020 | An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913,… |
| CVE-2020-0638 | Alta (7.8) | 2.4% | ⚠ Explotación activa | 14 ene 2020 | An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update… |
| CVE-2022-26904 | Alta (7) | 17% | ⚠ Explotación activa | 15 abr 2022 | Windows User Profile Service Elevation of Privilege Vulnerability |
| CVE-2021-40450 | Alta (7.8) | 1.6% | ⚠ Explotación activa | 13 oct 2021 | Win32k Elevation of Privilege Vulnerability |
| CVE-2022-21919 | Alta (7) | 2.4% | ⚠ Explotación activa | 11 ene 2022 | Windows User Profile Service Elevation of Privilege Vulnerability |
| CVE-2022-22718 | Alta (7.8) | 18% | ⚠ Explotación activa | 9 feb 2022 | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2022-24521 | Alta (7.8) | 7.1% | ⚠ Explotación activa | 15 abr 2022 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2021-34484 | Alta (7.8) | 22% | ⚠ Explotación activa | 12 ago 2021 | Windows User Profile Service Elevation of Privilege Vulnerability |
| CVE-2021-34486 | Alta (7.8) | 9.3% | ⚠ Explotación activa | 12 ago 2021 | Windows Event Tracing Elevation of Privilege Vulnerability |
| CVE-2022-21999 | Alta (7.8) | 41% | ⚠ Explotación activa | 9 feb 2022 | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2021-41379 | Alta (7.8) | 19% | ⚠ Explotación activa | 10 nov 2021 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2021-36934 | Alta (7.8) | 67% | ⚠ Explotación activa | 22 jul 2021 | An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully… |
| CVE-2020-0796 | Crítica (10) | 100% | ⚠ Explotación activa | 12 mar 2020 | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'. |
| CVE-2022-21882 | Alta (7.8) | 59% | ⚠ Explotación activa | 11 ene 2022 | Win32k Elevation of Privilege Vulnerability |
| CVE-2020-0787 | Alta (7.8) | 43% | ⚠ Explotación activa | 12 mar 2020 | An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of… |
| CVE-2013-3900 | Alta (8.8) | 45% | ⚠ Explotación activa | 11 dic 2013 | Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-38396 | Alta (7.8) | 0.41% | — | 12 feb 2023 | HP Factory Preinstalled Images on certain systems that shipped with Windows 10 versions 20H2 and earlier OS versions might allow escalation of privilege via execution of certain files outside the restricted path. This… |
| CVE-2022-26934 | Media (6.5) | 3.1% | — | 10 may 2022 | Windows Graphics Component Information Disclosure Vulnerability |
| CVE-2022-26925 | Media (5.9) | 10% | ⚠ Explotación activa | 10 may 2022 | Windows LSA Spoofing Vulnerability |
| CVE-2022-26923 | Alta (8.8) | 84% | ⚠ Explotación activa | 10 may 2022 | Active Directory Domain Services Elevation of Privilege Vulnerability |
| CVE-2022-26904 | Alta (7) | 17% | ⚠ Explotación activa | 15 abr 2022 | Windows User Profile Service Elevation of Privilege Vulnerability |
| CVE-2022-24521 | Alta (7.8) | 7.1% | ⚠ Explotación activa | 15 abr 2022 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2022-22718 | Alta (7.8) | 18% | ⚠ Explotación activa | 9 feb 2022 | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2022-21999 | Alta (7.8) | 41% | ⚠ Explotación activa | 9 feb 2022 | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2022-21971 | Alta (7.8) | 54% | ⚠ Explotación activa | 9 feb 2022 | Windows Runtime Remote Code Execution Vulnerability |
| CVE-2022-21919 | Alta (7) | 2.4% | ⚠ Explotación activa | 11 ene 2022 | Windows User Profile Service Elevation of Privilege Vulnerability |
| CVE-2022-21882 | Alta (7.8) | 59% | ⚠ Explotación activa | 11 ene 2022 | Win32k Elevation of Privilege Vulnerability |
| CVE-2022-21871 | Alta (7.8) | 0.68% | — | 11 ene 2022 | Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability |
| CVE-2021-43226 | Alta (7.8) | 3.1% | ⚠ Explotación activa | 15 dic 2021 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2021-41379 | Alta (7.8) | 19% | ⚠ Explotación activa | 10 nov 2021 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2021-40450 | Alta (7.8) | 1.6% | ⚠ Explotación activa | 13 oct 2021 | Win32k Elevation of Privilege Vulnerability |
| CVE-2021-40449 | Alta (7.8) | 74% | ⚠ Explotación activa | 13 oct 2021 | Win32k Elevation of Privilege Vulnerability |
| CVE-2021-40444 | Alta (7.8) | 97% | ⚠ Explotación activa | 15 sept 2021 | Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using… |
| CVE-2021-36955 | Alta (7.8) | 4.0% | ⚠ Explotación activa | 15 sept 2021 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2021-36948 | Alta (7.8) | 23% | ⚠ Explotación activa | 12 ago 2021 | Windows Update Medic Service Elevation of Privilege Vulnerability |
| CVE-2021-34486 | Alta (7.8) | 9.3% | ⚠ Explotación activa | 12 ago 2021 | Windows Event Tracing Elevation of Privilege Vulnerability |
| CVE-2021-34484 | Alta (7.8) | 22% | ⚠ Explotación activa | 12 ago 2021 | Windows User Profile Service Elevation of Privilege Vulnerability |
| CVE-2021-36934 | Alta (7.8) | 67% | ⚠ Explotación activa | 22 jul 2021 | An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully… |
| CVE-2021-34448 | Alta (8.8) | 40% | ⚠ Explotación activa | 16 jul 2021 | Scripting Engine Memory Corruption Vulnerability |
| CVE-2021-33771 | Alta (7.8) | 10% | ⚠ Explotación activa | 14 jul 2021 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2021-31979 | Alta (7.8) | 4.5% | ⚠ Explotación activa | 14 jul 2021 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2021-33742 | Alta (8.8) | 59% | ⚠ Explotación activa | 8 jun 2021 | Windows MSHTML Platform Remote Code Execution Vulnerability |
| CVE-2021-33739 | Alta (7.8) | 6.6% | ⚠ Explotación activa | 8 jun 2021 | Microsoft DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2021-31956 | Alta (7.8) | 22% | ⚠ Explotación activa | 8 jun 2021 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2021-31955 | Media (5.5) | 81% | ⚠ Explotación activa | 8 jun 2021 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2021-31201 | Alta (7.8) | 2.6% | ⚠ Explotación activa | 8 jun 2021 | Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.