Microsoft
Microsoft Windows 10: vulnerabilidades y CVE
Microsoft Windows 10 tiene 2979 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 67 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE2979
Últimos 12 meses2
Críticas67
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2015-1769 | Media (6.6) | 4.1% | ⚠ Explotación activa | 15 ago 2015 | Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks,… |
| CVE-2015-2426 | Alta (8.8) | 87% | ⚠ Explotación activa | 20 jul 2015 | Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-15929 | Alta (7.1) | 0.27% | — | 30 jul 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection. This issue affects SmartShare: through 2.3.1712.1202, which is… |
| CVE-2025-61303 | Crítica (9.8) | 0.46% | — | 20 oct 2025 | Hatching Triage Sandbox Windows 10 build 2004 (2025-08-14) and Windows 10 LTSC 2021(2025-08-14) contains a vulnerability in its Windows behavioral analysis engine that allows a submitted malware sample to evade… |
| CVE-2024-6769 | Alta (8.4) | 1.1% | — | 26 sept 2024 | A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious… |
| CVE-2024-6768 | Media (6.8) | 2.5% | — | 12 ago 2024 | A Denial of Service in CLFS.sys in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated low-privilege user to cause a Blue Screen of Death… |
| CVE-2017-20190 | Sin puntuar | 0.26% | — | 27 mar 2024 | Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side performance degradation during processing of multiple Unicode combining characters, aka a "Zalgo text" attack. NOTE: third… |
| CVE-2023-36697 | Alta (8) | 2.1% | — | 10 oct 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
| CVE-2023-36606 | Alta (7.5) | 67% | — | 10 oct 2023 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
| CVE-2023-36593 | Alta (7.3) | 0.99% | — | 10 oct 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
| CVE-2023-36592 | Alta (7.3) | 0.97% | — | 10 oct 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
| CVE-2023-36591 | Alta (7.3) | 0.92% | — | 10 oct 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
| CVE-2023-36590 | Alta (7.3) | 0.98% | — | 10 oct 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
| CVE-2023-36589 | Alta (7.3) | 0.97% | — | 10 oct 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
| CVE-2023-36583 | Alta (7.3) | 0.98% | — | 10 oct 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
| CVE-2023-36582 | Alta (7.3) | 0.98% | — | 10 oct 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
| CVE-2023-36581 | Alta (7.5) | 2.4% | — | 10 oct 2023 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
| CVE-2023-44216 | Media (5.3) | 1.6% | — | 27 sept 2023 | PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter… |
| CVE-2023-36913 | Alta (7.5) | 1.7% | — | 8 ago 2023 | Microsoft Message Queuing Information Disclosure Vulnerability |
| CVE-2023-36912 | Alta (7.5) | 2.1% | — | 8 ago 2023 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
| CVE-2023-36911 | Crítica (9.8) | 1.7% | — | 8 ago 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
| CVE-2023-36910 | Crítica (9.8) | 2.5% | — | 8 ago 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
| CVE-2023-36909 | Media (6.5) | 2.1% | — | 8 ago 2023 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
| CVE-2023-36908 | Media (6.5) | 0.97% | — | 8 ago 2023 | Windows Hyper-V Information Disclosure Vulnerability |
| CVE-2023-36907 | Alta (7.5) | 1.7% | — | 8 ago 2023 | Windows Cryptographic Services Information Disclosure Vulnerability |
| CVE-2023-36906 | Alta (7.5) | 2.0% | — | 8 ago 2023 | Windows Cryptographic Services Information Disclosure Vulnerability |
| CVE-2023-36905 | Alta (7.5) | 1.7% | — | 8 ago 2023 | Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability |
| CVE-2023-36903 | Crítica (9.8) | 1.6% | — | 8 ago 2023 | Windows System Assessment Tool Elevation of Privilege Vulnerability |
| CVE-2023-36900 | Alta (7.8) | 11% | — | 8 ago 2023 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2023-21712 | Alta (8.1) | 0.99% | — | 27 abr 2023 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability |
| CVE-2023-24859 | Alta (7.5) | 1.7% | — | 14 mar 2023 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability |
| CVE-2023-24858 | Alta (7.5) | 1.4% | — | 14 mar 2023 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.