Microsoft
Microsoft Windows 10 1909: vulnerabilities and CVEs
Microsoft Windows 10 1909 has 47 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 44 are listed by CISA as actively exploited.
CVEs47
Last 12 months0
Critical1
Actively exploited44
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43226 | High (7.8) | 3.1% | ⚠ Active exploitation | Dec 15, 2021 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2022-21971 | High (7.8) | 54% | ⚠ Active exploitation | Feb 9, 2022 | Windows Runtime Remote Code Execution Vulnerability |
| CVE-2022-26923 | High (8.8) | 84% | ⚠ Active exploitation | May 10, 2022 | Active Directory Domain Services Elevation of Privilege Vulnerability |
| CVE-2022-26925 | Medium (5.9) | 10% | ⚠ Active exploitation | May 10, 2022 | Windows LSA Spoofing Vulnerability |
| CVE-2020-0638 | High (7.8) | 2.4% | ⚠ Active exploitation | Jan 14, 2020 | An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update… |
| CVE-2020-1027 | High (7.8) | 4.5% | ⚠ Active exploitation | Apr 15, 2020 | An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913,… |
| CVE-2022-26904 | High (7) | 17% | ⚠ Active exploitation | Apr 15, 2022 | Windows User Profile Service Elevation of Privilege Vulnerability |
| CVE-2021-40450 | High (7.8) | 1.6% | ⚠ Active exploitation | Oct 13, 2021 | Win32k Elevation of Privilege Vulnerability |
| CVE-2022-21919 | High (7) | 2.4% | ⚠ Active exploitation | Jan 11, 2022 | Windows User Profile Service Elevation of Privilege Vulnerability |
| CVE-2022-22718 | High (7.8) | 18% | ⚠ Active exploitation | Feb 9, 2022 | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2022-24521 | High (7.8) | 7.1% | ⚠ Active exploitation | Apr 15, 2022 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2021-34484 | High (7.8) | 22% | ⚠ Active exploitation | Aug 12, 2021 | Windows User Profile Service Elevation of Privilege Vulnerability |
| CVE-2021-34486 | High (7.8) | 9.3% | ⚠ Active exploitation | Aug 12, 2021 | Windows Event Tracing Elevation of Privilege Vulnerability |
| CVE-2022-21999 | High (7.8) | 41% | ⚠ Active exploitation | Feb 9, 2022 | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2021-41379 | High (7.8) | 19% | ⚠ Active exploitation | Nov 10, 2021 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2021-36934 | High (7.8) | 67% | ⚠ Active exploitation | Jul 22, 2021 | An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully… |
| CVE-2020-0796 | Critical (10) | 100% | ⚠ Active exploitation | Mar 12, 2020 | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'. |
| CVE-2022-21882 | High (7.8) | 59% | ⚠ Active exploitation | Jan 11, 2022 | Win32k Elevation of Privilege Vulnerability |
| CVE-2020-0787 | High (7.8) | 43% | ⚠ Active exploitation | Mar 12, 2020 | An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of… |
| CVE-2013-3900 | High (8.8) | 45% | ⚠ Active exploitation | Dec 11, 2013 | Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38396 | High (7.8) | 0.41% | — | Feb 12, 2023 | HP Factory Preinstalled Images on certain systems that shipped with Windows 10 versions 20H2 and earlier OS versions might allow escalation of privilege via execution of certain files outside the restricted path. This… |
| CVE-2022-26934 | Medium (6.5) | 3.1% | — | May 10, 2022 | Windows Graphics Component Information Disclosure Vulnerability |
| CVE-2022-26925 | Medium (5.9) | 10% | ⚠ Active exploitation | May 10, 2022 | Windows LSA Spoofing Vulnerability |
| CVE-2022-26923 | High (8.8) | 84% | ⚠ Active exploitation | May 10, 2022 | Active Directory Domain Services Elevation of Privilege Vulnerability |
| CVE-2022-26904 | High (7) | 17% | ⚠ Active exploitation | Apr 15, 2022 | Windows User Profile Service Elevation of Privilege Vulnerability |
| CVE-2022-24521 | High (7.8) | 7.1% | ⚠ Active exploitation | Apr 15, 2022 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2022-22718 | High (7.8) | 18% | ⚠ Active exploitation | Feb 9, 2022 | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2022-21999 | High (7.8) | 41% | ⚠ Active exploitation | Feb 9, 2022 | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2022-21971 | High (7.8) | 54% | ⚠ Active exploitation | Feb 9, 2022 | Windows Runtime Remote Code Execution Vulnerability |
| CVE-2022-21919 | High (7) | 2.4% | ⚠ Active exploitation | Jan 11, 2022 | Windows User Profile Service Elevation of Privilege Vulnerability |
| CVE-2022-21882 | High (7.8) | 59% | ⚠ Active exploitation | Jan 11, 2022 | Win32k Elevation of Privilege Vulnerability |
| CVE-2022-21871 | High (7.8) | 0.68% | — | Jan 11, 2022 | Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability |
| CVE-2021-43226 | High (7.8) | 3.1% | ⚠ Active exploitation | Dec 15, 2021 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2021-41379 | High (7.8) | 19% | ⚠ Active exploitation | Nov 10, 2021 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2021-40450 | High (7.8) | 1.6% | ⚠ Active exploitation | Oct 13, 2021 | Win32k Elevation of Privilege Vulnerability |
| CVE-2021-40449 | High (7.8) | 74% | ⚠ Active exploitation | Oct 13, 2021 | Win32k Elevation of Privilege Vulnerability |
| CVE-2021-40444 | High (7.8) | 97% | ⚠ Active exploitation | Sep 15, 2021 | Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using… |
| CVE-2021-36955 | High (7.8) | 4.0% | ⚠ Active exploitation | Sep 15, 2021 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2021-36948 | High (7.8) | 23% | ⚠ Active exploitation | Aug 12, 2021 | Windows Update Medic Service Elevation of Privilege Vulnerability |
| CVE-2021-34486 | High (7.8) | 9.3% | ⚠ Active exploitation | Aug 12, 2021 | Windows Event Tracing Elevation of Privilege Vulnerability |
| CVE-2021-34484 | High (7.8) | 22% | ⚠ Active exploitation | Aug 12, 2021 | Windows User Profile Service Elevation of Privilege Vulnerability |
| CVE-2021-36934 | High (7.8) | 67% | ⚠ Active exploitation | Jul 22, 2021 | An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully… |
| CVE-2021-34448 | High (8.8) | 40% | ⚠ Active exploitation | Jul 16, 2021 | Scripting Engine Memory Corruption Vulnerability |
| CVE-2021-33771 | High (7.8) | 10% | ⚠ Active exploitation | Jul 14, 2021 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2021-31979 | High (7.8) | 4.5% | ⚠ Active exploitation | Jul 14, 2021 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2021-33742 | High (8.8) | 59% | ⚠ Active exploitation | Jun 8, 2021 | Windows MSHTML Platform Remote Code Execution Vulnerability |
| CVE-2021-33739 | High (7.8) | 6.6% | ⚠ Active exploitation | Jun 8, 2021 | Microsoft DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2021-31956 | High (7.8) | 22% | ⚠ Active exploitation | Jun 8, 2021 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2021-31955 | Medium (5.5) | 81% | ⚠ Active exploitation | Jun 8, 2021 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2021-31201 | High (7.8) | 2.6% | ⚠ Active exploitation | Jun 8, 2021 | Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.