« Volver al listado

Microsoft

Microsoft Windows 10: vulnerabilidades y CVE

Microsoft Windows 10 tiene 2979 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 67 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE2979
Últimos 12 meses2
Críticas67
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2015-1769Media (6.6)4.1%⚠ Explotación activa15 ago 2015
Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks,…
CVE-2015-2426Alta (8.8)87%⚠ Explotación activa20 jul 2015
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-15929Alta (7.1)0.27%—30 jul 2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection. This issue affects SmartShare: through 2.3.1712.1202, which is…
CVE-2025-61303Crítica (9.8)0.46%—20 oct 2025
Hatching Triage Sandbox Windows 10 build 2004 (2025-08-14) and Windows 10 LTSC 2021(2025-08-14) contains a vulnerability in its Windows behavioral analysis engine that allows a submitted malware sample to evade…
CVE-2024-6769Alta (8.4)1.1%—26 sept 2024
A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious…
CVE-2024-6768Media (6.8)2.5%—12 ago 2024
A Denial of Service in CLFS.sys in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated low-privilege user to cause a Blue Screen of Death…
CVE-2017-20190Sin puntuar0.26%—27 mar 2024
Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side performance degradation during processing of multiple Unicode combining characters, aka a "Zalgo text" attack. NOTE: third…
CVE-2023-36697Alta (8)2.1%—10 oct 2023
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2023-36606Alta (7.5)67%—10 oct 2023
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVE-2023-36593Alta (7.3)0.99%—10 oct 2023
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2023-36592Alta (7.3)0.97%—10 oct 2023
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2023-36591Alta (7.3)0.92%—10 oct 2023
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2023-36590Alta (7.3)0.98%—10 oct 2023
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2023-36589Alta (7.3)0.97%—10 oct 2023
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2023-36583Alta (7.3)0.98%—10 oct 2023
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2023-36582Alta (7.3)0.98%—10 oct 2023
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2023-36581Alta (7.5)2.4%—10 oct 2023
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVE-2023-44216Media (5.3)1.6%—27 sept 2023
PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter…
CVE-2023-36913Alta (7.5)1.7%—8 ago 2023
Microsoft Message Queuing Information Disclosure Vulnerability
CVE-2023-36912Alta (7.5)2.1%—8 ago 2023
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVE-2023-36911Crítica (9.8)1.7%—8 ago 2023
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2023-36910Crítica (9.8)2.5%—8 ago 2023
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2023-36909Media (6.5)2.1%—8 ago 2023
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVE-2023-36908Media (6.5)0.97%—8 ago 2023
Windows Hyper-V Information Disclosure Vulnerability
CVE-2023-36907Alta (7.5)1.7%—8 ago 2023
Windows Cryptographic Services Information Disclosure Vulnerability
CVE-2023-36906Alta (7.5)2.0%—8 ago 2023
Windows Cryptographic Services Information Disclosure Vulnerability
CVE-2023-36905Alta (7.5)1.7%—8 ago 2023
Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability
CVE-2023-36903Crítica (9.8)1.6%—8 ago 2023
Windows System Assessment Tool Elevation of Privilege Vulnerability
CVE-2023-36900Alta (7.8)11%—8 ago 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2023-21712Alta (8.1)0.99%—27 abr 2023
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
CVE-2023-24859Alta (7.5)1.7%—14 mar 2023
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
CVE-2023-24858Alta (7.5)1.4%—14 mar 2023
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation8
  2. T1499.004 Application or System Exploitation6
  3. T1574 Hijack Execution Flow6
  4. T1565 Data Manipulation3
  5. T1005 Data from Local System2
  6. T1204.002 Malicious File2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft