« Back to list

Microsoft

Microsoft Windows 10 1909: vulnerabilities and CVEs

Microsoft Windows 10 1909 has 47 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 44 are listed by CISA as actively exploited.

CVEs47
Last 12 months0
Critical1
Actively exploited44

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2021-43226High (7.8)3.1%⚠ Active exploitationDec 15, 2021
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2022-21971High (7.8)54%⚠ Active exploitationFeb 9, 2022
Windows Runtime Remote Code Execution Vulnerability
CVE-2022-26923High (8.8)84%⚠ Active exploitationMay 10, 2022
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2022-26925Medium (5.9)10%⚠ Active exploitationMay 10, 2022
Windows LSA Spoofing Vulnerability
CVE-2020-0638High (7.8)2.4%⚠ Active exploitationJan 14, 2020
An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update…
CVE-2020-1027High (7.8)4.5%⚠ Active exploitationApr 15, 2020
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913,…
CVE-2022-26904High (7)17%⚠ Active exploitationApr 15, 2022
Windows User Profile Service Elevation of Privilege Vulnerability
CVE-2021-40450High (7.8)1.6%⚠ Active exploitationOct 13, 2021
Win32k Elevation of Privilege Vulnerability
CVE-2022-21919High (7)2.4%⚠ Active exploitationJan 11, 2022
Windows User Profile Service Elevation of Privilege Vulnerability
CVE-2022-22718High (7.8)18%⚠ Active exploitationFeb 9, 2022
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2022-24521High (7.8)7.1%⚠ Active exploitationApr 15, 2022
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-34484High (7.8)22%⚠ Active exploitationAug 12, 2021
Windows User Profile Service Elevation of Privilege Vulnerability
CVE-2021-34486High (7.8)9.3%⚠ Active exploitationAug 12, 2021
Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2022-21999High (7.8)41%⚠ Active exploitationFeb 9, 2022
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2021-41379High (7.8)19%⚠ Active exploitationNov 10, 2021
Windows Installer Elevation of Privilege Vulnerability
CVE-2021-36934High (7.8)67%⚠ Active exploitationJul 22, 2021
An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully…
CVE-2020-0796Critical (10)100%⚠ Active exploitationMar 12, 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.
CVE-2022-21882High (7.8)59%⚠ Active exploitationJan 11, 2022
Win32k Elevation of Privilege Vulnerability
CVE-2020-0787High (7.8)43%⚠ Active exploitationMar 12, 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of…
CVE-2013-3900High (8.8)45%⚠ Active exploitationDec 11, 2013
Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2022-38396High (7.8)0.41%—Feb 12, 2023
HP Factory Preinstalled Images on certain systems that shipped with Windows 10 versions 20H2 and earlier OS versions might allow escalation of privilege via execution of certain files outside the restricted path. This…
CVE-2022-26934Medium (6.5)3.1%—May 10, 2022
Windows Graphics Component Information Disclosure Vulnerability
CVE-2022-26925Medium (5.9)10%⚠ Active exploitationMay 10, 2022
Windows LSA Spoofing Vulnerability
CVE-2022-26923High (8.8)84%⚠ Active exploitationMay 10, 2022
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2022-26904High (7)17%⚠ Active exploitationApr 15, 2022
Windows User Profile Service Elevation of Privilege Vulnerability
CVE-2022-24521High (7.8)7.1%⚠ Active exploitationApr 15, 2022
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2022-22718High (7.8)18%⚠ Active exploitationFeb 9, 2022
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2022-21999High (7.8)41%⚠ Active exploitationFeb 9, 2022
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2022-21971High (7.8)54%⚠ Active exploitationFeb 9, 2022
Windows Runtime Remote Code Execution Vulnerability
CVE-2022-21919High (7)2.4%⚠ Active exploitationJan 11, 2022
Windows User Profile Service Elevation of Privilege Vulnerability
CVE-2022-21882High (7.8)59%⚠ Active exploitationJan 11, 2022
Win32k Elevation of Privilege Vulnerability
CVE-2022-21871High (7.8)0.68%—Jan 11, 2022
Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability
CVE-2021-43226High (7.8)3.1%⚠ Active exploitationDec 15, 2021
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-41379High (7.8)19%⚠ Active exploitationNov 10, 2021
Windows Installer Elevation of Privilege Vulnerability
CVE-2021-40450High (7.8)1.6%⚠ Active exploitationOct 13, 2021
Win32k Elevation of Privilege Vulnerability
CVE-2021-40449High (7.8)74%⚠ Active exploitationOct 13, 2021
Win32k Elevation of Privilege Vulnerability
CVE-2021-40444High (7.8)97%⚠ Active exploitationSep 15, 2021
Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using…
CVE-2021-36955High (7.8)4.0%⚠ Active exploitationSep 15, 2021
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-36948High (7.8)23%⚠ Active exploitationAug 12, 2021
Windows Update Medic Service Elevation of Privilege Vulnerability
CVE-2021-34486High (7.8)9.3%⚠ Active exploitationAug 12, 2021
Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-34484High (7.8)22%⚠ Active exploitationAug 12, 2021
Windows User Profile Service Elevation of Privilege Vulnerability
CVE-2021-36934High (7.8)67%⚠ Active exploitationJul 22, 2021
An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully…
CVE-2021-34448High (8.8)40%⚠ Active exploitationJul 16, 2021
Scripting Engine Memory Corruption Vulnerability
CVE-2021-33771High (7.8)10%⚠ Active exploitationJul 14, 2021
Windows Kernel Elevation of Privilege Vulnerability
CVE-2021-31979High (7.8)4.5%⚠ Active exploitationJul 14, 2021
Windows Kernel Elevation of Privilege Vulnerability
CVE-2021-33742High (8.8)59%⚠ Active exploitationJun 8, 2021
Windows MSHTML Platform Remote Code Execution Vulnerability
CVE-2021-33739High (7.8)6.6%⚠ Active exploitationJun 8, 2021
Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2021-31956High (7.8)22%⚠ Active exploitationJun 8, 2021
Windows NTFS Elevation of Privilege Vulnerability
CVE-2021-31955Medium (5.5)81%⚠ Active exploitationJun 8, 2021
Windows Kernel Information Disclosure Vulnerability
CVE-2021-31201High (7.8)2.6%⚠ Active exploitationJun 8, 2021
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

🎯 How it gets exploited (ATT&CK techniques)

  1. T1068 Exploitation for Privilege Escalation35
  2. T1059 Command and Scripting Interpreter21
  3. T1059.001 PowerShell6
  4. T1203 Exploitation for Client Execution6
  5. T1190 Exploit Public-Facing Application2
  6. T1548 Abuse Elevation Control Mechanism2

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

🏴 Groups known to exploit this technology

Other products by Microsoft