Microsoft
Microsoft Windows 10 2004: vulnerabilidades y CVE
Microsoft Windows 10 2004 tiene 28 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 27 figuran en el catálogo de explotación activa de CISA.
CVE28
Últimos 12 meses0
Críticas1
Explotadas activamente27
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-43226 | Alta (7.8) | 3.1% | ⚠ Explotación activa | 15 dic 2021 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2021-41357 | Alta (7.8) | 1.6% | ⚠ Explotación activa | 13 oct 2021 | Win32k Elevation of Privilege Vulnerability |
| CVE-2021-40450 | Alta (7.8) | 1.6% | ⚠ Explotación activa | 13 oct 2021 | Win32k Elevation of Privilege Vulnerability |
| CVE-2021-31166 | Crítica (9.8) | 100% | ⚠ Explotación activa | 11 may 2021 | HTTP Protocol Stack Remote Code Execution Vulnerability |
| CVE-2021-34484 | Alta (7.8) | 22% | ⚠ Explotación activa | 12 ago 2021 | Windows User Profile Service Elevation of Privilege Vulnerability |
| CVE-2021-34486 | Alta (7.8) | 9.3% | ⚠ Explotación activa | 12 ago 2021 | Windows Event Tracing Elevation of Privilege Vulnerability |
| CVE-2021-41379 | Alta (7.8) | 19% | ⚠ Explotación activa | 10 nov 2021 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2021-36934 | Alta (7.8) | 67% | ⚠ Explotación activa | 22 jul 2021 | An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully… |
| CVE-2021-40449 | Alta (7.8) | 74% | ⚠ Explotación activa | 13 oct 2021 | Win32k Elevation of Privilege Vulnerability |
| CVE-2021-40444 | Alta (7.8) | 97% | ⚠ Explotación activa | 15 sept 2021 | Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using… |
| CVE-2020-0986 | Alta (7.8) | 16% | ⚠ Explotación activa | 9 jun 2020 | An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237,… |
| CVE-2020-1464 | Media (5.5) | 39% | ⚠ Explotación activa | 17 ago 2020 | A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack… |
| CVE-2020-17087 | Alta (7.8) | 5.4% | ⚠ Explotación activa | 11 nov 2020 | Windows Kernel Local Elevation of Privilege Vulnerability |
| CVE-2021-1732 | Alta (7.8) | 78% | ⚠ Explotación activa | 25 feb 2021 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2021-28310 | Alta (7.8) | 8.3% | ⚠ Explotación activa | 13 abr 2021 | Win32k Elevation of Privilege Vulnerability |
| CVE-2021-36955 | Alta (7.8) | 4.0% | ⚠ Explotación activa | 15 sept 2021 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2021-31199 | Alta (7.8) | 3.0% | ⚠ Explotación activa | 8 jun 2021 | Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability |
| CVE-2021-31956 | Alta (7.8) | 22% | ⚠ Explotación activa | 8 jun 2021 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2021-31201 | Alta (7.8) | 2.6% | ⚠ Explotación activa | 8 jun 2021 | Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability |
| CVE-2021-31955 | Media (5.5) | 81% | ⚠ Explotación activa | 8 jun 2021 | Windows Kernel Information Disclosure Vulnerability |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-38396 | Alta (7.8) | 0.41% | — | 12 feb 2023 | HP Factory Preinstalled Images on certain systems that shipped with Windows 10 versions 20H2 and earlier OS versions might allow escalation of privilege via execution of certain files outside the restricted path. This… |
| CVE-2021-43226 | Alta (7.8) | 3.1% | ⚠ Explotación activa | 15 dic 2021 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2021-41379 | Alta (7.8) | 19% | ⚠ Explotación activa | 10 nov 2021 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2021-41357 | Alta (7.8) | 1.6% | ⚠ Explotación activa | 13 oct 2021 | Win32k Elevation of Privilege Vulnerability |
| CVE-2021-40450 | Alta (7.8) | 1.6% | ⚠ Explotación activa | 13 oct 2021 | Win32k Elevation of Privilege Vulnerability |
| CVE-2021-40449 | Alta (7.8) | 74% | ⚠ Explotación activa | 13 oct 2021 | Win32k Elevation of Privilege Vulnerability |
| CVE-2021-40444 | Alta (7.8) | 97% | ⚠ Explotación activa | 15 sept 2021 | Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using… |
| CVE-2021-36955 | Alta (7.8) | 4.0% | ⚠ Explotación activa | 15 sept 2021 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2021-36948 | Alta (7.8) | 23% | ⚠ Explotación activa | 12 ago 2021 | Windows Update Medic Service Elevation of Privilege Vulnerability |
| CVE-2021-34486 | Alta (7.8) | 9.3% | ⚠ Explotación activa | 12 ago 2021 | Windows Event Tracing Elevation of Privilege Vulnerability |
| CVE-2021-34484 | Alta (7.8) | 22% | ⚠ Explotación activa | 12 ago 2021 | Windows User Profile Service Elevation of Privilege Vulnerability |
| CVE-2021-36934 | Alta (7.8) | 67% | ⚠ Explotación activa | 22 jul 2021 | An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully… |
| CVE-2021-34448 | Alta (8.8) | 40% | ⚠ Explotación activa | 16 jul 2021 | Scripting Engine Memory Corruption Vulnerability |
| CVE-2021-33771 | Alta (7.8) | 10% | ⚠ Explotación activa | 14 jul 2021 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2021-31979 | Alta (7.8) | 4.5% | ⚠ Explotación activa | 14 jul 2021 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2021-33742 | Alta (8.8) | 59% | ⚠ Explotación activa | 8 jun 2021 | Windows MSHTML Platform Remote Code Execution Vulnerability |
| CVE-2021-33739 | Alta (7.8) | 6.6% | ⚠ Explotación activa | 8 jun 2021 | Microsoft DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2021-31956 | Alta (7.8) | 22% | ⚠ Explotación activa | 8 jun 2021 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2021-31955 | Media (5.5) | 81% | ⚠ Explotación activa | 8 jun 2021 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2021-31201 | Alta (7.8) | 2.6% | ⚠ Explotación activa | 8 jun 2021 | Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability |
| CVE-2021-31199 | Alta (7.8) | 3.0% | ⚠ Explotación activa | 8 jun 2021 | Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability |
| CVE-2021-1675 | Alta (7.8) | 85% | ⚠ Explotación activa | 8 jun 2021 | Windows Print Spooler Remote Code Execution Vulnerability |
| CVE-2021-31166 | Crítica (9.8) | 100% | ⚠ Explotación activa | 11 may 2021 | HTTP Protocol Stack Remote Code Execution Vulnerability |
| CVE-2021-28310 | Alta (7.8) | 8.3% | ⚠ Explotación activa | 13 abr 2021 | Win32k Elevation of Privilege Vulnerability |
| CVE-2021-1732 | Alta (7.8) | 78% | ⚠ Explotación activa | 25 feb 2021 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2020-17087 | Alta (7.8) | 5.4% | ⚠ Explotación activa | 11 nov 2020 | Windows Kernel Local Elevation of Privilege Vulnerability |
| CVE-2020-1464 | Media (5.5) | 39% | ⚠ Explotación activa | 17 ago 2020 | A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack… |
| CVE-2020-0986 | Alta (7.8) | 16% | ⚠ Explotación activa | 9 jun 2020 | An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237,… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.