« Volver al listado

Microsoft

Microsoft Windows 10 1909: vulnerabilidades y CVE

Microsoft Windows 10 1909 tiene 47 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 44 figuran en el catálogo de explotación activa de CISA.

CVE47
Últimos 12 meses0
Críticas1
Explotadas activamente44

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2021-43226Alta (7.8)3.1%⚠ Explotación activa15 dic 2021
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2022-21971Alta (7.8)54%⚠ Explotación activa9 feb 2022
Windows Runtime Remote Code Execution Vulnerability
CVE-2022-26923Alta (8.8)84%⚠ Explotación activa10 may 2022
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2022-26925Media (5.9)10%⚠ Explotación activa10 may 2022
Windows LSA Spoofing Vulnerability
CVE-2020-1027Alta (7.8)4.5%⚠ Explotación activa15 abr 2020
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913,…
CVE-2020-0638Alta (7.8)2.4%⚠ Explotación activa14 ene 2020
An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update…
CVE-2022-26904Alta (7)17%⚠ Explotación activa15 abr 2022
Windows User Profile Service Elevation of Privilege Vulnerability
CVE-2021-40450Alta (7.8)1.6%⚠ Explotación activa13 oct 2021
Win32k Elevation of Privilege Vulnerability
CVE-2022-21919Alta (7)2.4%⚠ Explotación activa11 ene 2022
Windows User Profile Service Elevation of Privilege Vulnerability
CVE-2022-22718Alta (7.8)18%⚠ Explotación activa9 feb 2022
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2022-24521Alta (7.8)7.1%⚠ Explotación activa15 abr 2022
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-34484Alta (7.8)22%⚠ Explotación activa12 ago 2021
Windows User Profile Service Elevation of Privilege Vulnerability
CVE-2021-34486Alta (7.8)9.3%⚠ Explotación activa12 ago 2021
Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2022-21999Alta (7.8)41%⚠ Explotación activa9 feb 2022
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2021-41379Alta (7.8)19%⚠ Explotación activa10 nov 2021
Windows Installer Elevation of Privilege Vulnerability
CVE-2021-36934Alta (7.8)67%⚠ Explotación activa22 jul 2021
An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully…
CVE-2020-0796Crítica (10)100%⚠ Explotación activa12 mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.
CVE-2022-21882Alta (7.8)59%⚠ Explotación activa11 ene 2022
Win32k Elevation of Privilege Vulnerability
CVE-2020-0787Alta (7.8)43%⚠ Explotación activa12 mar 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of…
CVE-2013-3900Alta (8.8)45%⚠ Explotación activa11 dic 2013
Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2022-38396Alta (7.8)0.41%—12 feb 2023
HP Factory Preinstalled Images on certain systems that shipped with Windows 10 versions 20H2 and earlier OS versions might allow escalation of privilege via execution of certain files outside the restricted path. This…
CVE-2022-26934Media (6.5)3.1%—10 may 2022
Windows Graphics Component Information Disclosure Vulnerability
CVE-2022-26925Media (5.9)10%⚠ Explotación activa10 may 2022
Windows LSA Spoofing Vulnerability
CVE-2022-26923Alta (8.8)84%⚠ Explotación activa10 may 2022
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2022-26904Alta (7)17%⚠ Explotación activa15 abr 2022
Windows User Profile Service Elevation of Privilege Vulnerability
CVE-2022-24521Alta (7.8)7.1%⚠ Explotación activa15 abr 2022
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2022-22718Alta (7.8)18%⚠ Explotación activa9 feb 2022
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2022-21999Alta (7.8)41%⚠ Explotación activa9 feb 2022
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2022-21971Alta (7.8)54%⚠ Explotación activa9 feb 2022
Windows Runtime Remote Code Execution Vulnerability
CVE-2022-21919Alta (7)2.4%⚠ Explotación activa11 ene 2022
Windows User Profile Service Elevation of Privilege Vulnerability
CVE-2022-21882Alta (7.8)59%⚠ Explotación activa11 ene 2022
Win32k Elevation of Privilege Vulnerability
CVE-2022-21871Alta (7.8)0.68%—11 ene 2022
Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability
CVE-2021-43226Alta (7.8)3.1%⚠ Explotación activa15 dic 2021
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-41379Alta (7.8)19%⚠ Explotación activa10 nov 2021
Windows Installer Elevation of Privilege Vulnerability
CVE-2021-40450Alta (7.8)1.6%⚠ Explotación activa13 oct 2021
Win32k Elevation of Privilege Vulnerability
CVE-2021-40449Alta (7.8)74%⚠ Explotación activa13 oct 2021
Win32k Elevation of Privilege Vulnerability
CVE-2021-40444Alta (7.8)97%⚠ Explotación activa15 sept 2021
Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using…
CVE-2021-36955Alta (7.8)4.0%⚠ Explotación activa15 sept 2021
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-36948Alta (7.8)23%⚠ Explotación activa12 ago 2021
Windows Update Medic Service Elevation of Privilege Vulnerability
CVE-2021-34486Alta (7.8)9.3%⚠ Explotación activa12 ago 2021
Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-34484Alta (7.8)22%⚠ Explotación activa12 ago 2021
Windows User Profile Service Elevation of Privilege Vulnerability
CVE-2021-36934Alta (7.8)67%⚠ Explotación activa22 jul 2021
An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully…
CVE-2021-34448Alta (8.8)40%⚠ Explotación activa16 jul 2021
Scripting Engine Memory Corruption Vulnerability
CVE-2021-33771Alta (7.8)10%⚠ Explotación activa14 jul 2021
Windows Kernel Elevation of Privilege Vulnerability
CVE-2021-31979Alta (7.8)4.5%⚠ Explotación activa14 jul 2021
Windows Kernel Elevation of Privilege Vulnerability
CVE-2021-33742Alta (8.8)59%⚠ Explotación activa8 jun 2021
Windows MSHTML Platform Remote Code Execution Vulnerability
CVE-2021-33739Alta (7.8)6.6%⚠ Explotación activa8 jun 2021
Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2021-31956Alta (7.8)22%⚠ Explotación activa8 jun 2021
Windows NTFS Elevation of Privilege Vulnerability
CVE-2021-31955Media (5.5)81%⚠ Explotación activa8 jun 2021
Windows Kernel Information Disclosure Vulnerability
CVE-2021-31201Alta (7.8)2.6%⚠ Explotación activa8 jun 2021
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation30
  2. T1059 Command and Scripting Interpreter17
  3. T1203 Exploitation for Client Execution11
  4. T1059.001 PowerShell2
  5. T1190 Exploit Public-Facing Application2
  6. T1548 Abuse Elevation Control Mechanism2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

🏴 Grupos que explotan esta tecnología

📰 Noticias relacionadas

Otros productos de Microsoft